oy 


TM 32-220 


TECHNICAL MANUAL 


_~ BASIC CRYPTANALYTICS (U) 


a This material contains information affecting the National Defense 
of the United States within the meaning of the Espionage Laws, 
Title 18, U.S.C., Sections 793 and 794, the transmission or 


. Fevelation of which in any manner to an unauthorized person 
is prohibited by law. 


HEADQUARTERS, DEPARTMENT OF THE ARMY 
a | AUGUST 1970 


-—CONFIBENTIAL- — 


Excluded From Automatic 
| + Dewngrading and Deelassification 


NATIONAL SECURITY AGENCY 
CENTRAL SECURITY SERVICE 
FORT GEORGE G. MEADE, MARYLAND 20755-6000 


Serial: J9069-92 
4 March 1993 


Mr. William J. Neill 
1231 Crescendo Drive 
Roseville, CA 95678 


Dear Mr. Neill: 


This responds to your Freedom of Information Act (FOIA) 
request of 16 January 1992 for an original copy of TM 11-485 and 
the declassification and release of TM 32-220. Your request has 
been processed under the FOIA, and although we do not have an 
original of TM 11-485, a copy of that document is enclosed along 
with a copy of TM 32-220. Certain information, however, has been 
deleted from TM 32-220. 


Some of the information deleted from the TM 32-220 was found 
to be currently and properly classified in accordance with 
Executive Order 12356. This information meets the criteria for 
classification as set forth in subparagraphs (a)(2), (a)(4) and 
(a) (8) of section 1.3 and remains classified CONFIDENTIAL as 
provided in section 1.1 of Executive Order 12356. The 
information is classified because its disclosure could reasonably 
be expected to cause damage to the national security. Because 
the information is currently and properly classified, it is 
exempt from disclosure pursuant to the first exemption of the 
FOIA (5 U.S.C. section 552(b)(1)). 


In addition, this Agency is authorized by various statutes 
to protect certain information concerning its activities. We 
have determined that such information exists in TM 32-220. 
Accordingly, those portions are also exempt from disclosure 
pursuant to the third exemption of the FOIA which provides for 
the withholding of information specifically protected from 
disclosure by statute. The specific statutes applicable in this 
case are Title 18 U.S. Code 798; Title 50 U.S. Code 403(d) (3); 
and Section 6, Public Law 86-36 (50 U.S. Code 402 note). 


Since these deletions may be construed as a partial denial 
of your request, you are hereby advised of this Agency's appeal 
procedures. Any person denied access to information may, within 
60 days after notification of the denial, file an appeal to the 
NSA/CSS Freedom of Information Act Appeal Authority. The appeal 
shall be in writing addressed to the NSA/CSS FOIA Appeal 
Authority, National Security Agency, Fort George G. Meade, MD 
20755-6000. The appeal shall reference the initial denial of 


Serial: J9069-92 


access and shall contain, in sufficient detail and particularity, 
the grounds upon which the requester believes release of the 
information is required. The NSA/CSS Appeal Authority will 
respond to the appeal within 20 working days after receipt. 


On 5 February 1993, you spoke to a member of my staff who 
advised you that we anticipated costs of $100.00 to process your 
request, and you agreed to pay that amount. The actual fees 
incurred total $96.80. The search for records responsive to your 
request took 4 hours, and 412 pages are being released to you. 
You are allowed 2 hours of search and the duplication of 100 
pages at no cost pursuant to 5 U.S.C. 552 (4) (A) (iv) (II). The 
remaining charges are assessed in accordance with DoD Regulation 
5400.7-R, which assesses $25.00 per hour for search and $.15 per 
page for duplication. A bill for the total due will be sent to 
you under separate cover. 


Sincerely, 


anda. Tullow 
oeMICHAEL A. SMITH 
Director of Policy 


Encls: 
a/s 


oy 


TM 32-220 


TECHNICAL MANUAL 


_~ BASIC CRYPTANALYTICS (U) 


a This material contains information affecting the National Defense 
of the United States within the meaning of the Espionage Laws, 
Title 18, U.S.C., Sections 793 and 794, the transmission or 


. Fevelation of which in any manner to an unauthorized person 
is prohibited by law. 


HEADQUARTERS, DEPARTMENT OF THE ARMY 
a | AUGUST 1970 


-—CONFIBENTIAL- — 


Excluded From Automatic 
| + Dewngrading and Deelassification 


TrecunicaL Manuva 


No. 32-220 


PART ONE. 


CuaPrTer l. 
Section f. 
Il. 

Til. 
CuapTer 2. SE 


Section I. 
II, 
III. 


PART TWO. 


CuHaprer 3. 


Section I. 
II. 


Til. 


CHAPTER 4. 


Section I. 
Il. 


PART THREE. 


GRILLE TRANSPOSITION SYSTEMS 


CHAPTER 6. 
\ II. 


*TM 32-220 


HEADQUARTERS 


DEPARTMENT OF THE ARMY 
| Wasuineton, D.C., 20 August 1970 


BASIC CRYPTANALYTICS (U) 


INTRODUCTION TO CRYPTANALYTICS 


INTRODUCTION er 
Generaliciar tee oP aee ea ta a a a na en datia a Da cael I-1 
Terminology =a tec etteeneee cele eee cwse ce webe stoves secs delice es eee ateculesees ot 1 
Cryptographic:systems_- 222222. ecnseosse noe eee bes eee tee ce eee ce ete ee seuld 1 
CURITY OF CRYPTOGRAPHIC SYSTEMS 

General: Svs Sethe ete oe So ee a fee ele oe ial 2 
The-eryptanalytic:attackv2.: cA.esc eee eee eels sete ase secedte et ewids sed = 2 
Analytic sidsi2<. 5225-2 cotpetee sensi cwekac cle ceesen det ebeel see blo seetoms 2-1 


TRANSPOSITION SYSTEMS 
GENERAL TRANSPOSITION SYSTEMS 


Geéneralisis 6252s se cath lees ene ote eaoee esos etos oie see othiste te Sete gtees 3-1 
Rowite transposition-systems.-0.202 22. cbse eee at Ho ewe e eel eee eee chen Se 3-6 
Cohimnar transposition systems... 2222 2-46 s2act cee se recs nceine nen ewe cent nee eees o-9 


SOLUTION OF MONOPHASE TRANSPOSITION SYSTEMS 
Principles of solution...........----.----- eee ee ene 4 


Solution of incompletely filled matrices.___..__-.__--.---.-------.-----+------- eee 


MONO GRAPHIC SUBSTITUTION 3 YSTE MS 


Cuaprer 7. UNILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS USING STAND- 
ARD CIPHER ALPHABETS 
Section I. Basis of substitution systems_.__..--..----....------------------------------------ 7-1 
II. Uniliteral monoalphabetic substitution...........2.----------- ee eee 7-5 
III. Solution of uniliteral monoalphabetic ciphers using standard cipher alphabets__.__.._.-- 7-9 
CuaPter 8. UNILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS USING MIXED 
CIPHER ALPHABETS 
Section I. Generation and use of mixed cipher alphabets. ..._.....-..--..---.------------------ 8-1 
II. Recovery of mixed cipher alphabets__......_.. aiitcalve be cteie Let sed eee 8-5 
ITI. Solution of uniliteral monoalphabetic mixed alphabet CIDheTS2 Sooo tee Oct bess obs 8-10 
Cuaprer 9. MULTILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS 
Section I. Characteristics and types_.....-------- 2.02022 ee ne ee eee ee eee 9-1 
II. Analysis of multiliteral systems_.._.....-....2..-...---2--- 2-2 eee eee eee eee ee 9-5 
HI. Analysis of multiliteral with variants..............-2..---2-.2---------- = ee eee 9-9 
IV; .Multinomic ‘systems... oc 2. see ok oes ces ees ee See ee de Sate ne cde ecceeeshevnes 9-13 
PART FOUR. POLYGRAPHIC SUBSTITUTION SYSTEMS 

Cuarrer 10. CHARACTERISTICS OF POLYGRAPHIC SUBSTITUTION SYSTEMS 
Section I. Characteristics of polygraphic encipherment_..........-------.---------------------- 10-1 
II. Recognition and identification of polygraphic substitution_....-....--.-.-- hen ed AS 10-5 

Caarter 11. SOLUTION OF POLYGRAPHIC SUBSTITUTION SYSTEMS 

Section I. Analysis of digraphic ciphers.._...-....-._--.--------------------- eee ee eee li-1 
II. Analysis of two-square ciphers_._._....--.--.--------------------------- ee 11-4 
Til. Anslysis'of- Plsytairciphers:.c.scsc cece oe se cece bere seecel cewdedeseeeeeotue sees 11-7 


*This manual supersedes TM 32-220, 5 April 1950. 


—CONFIDENTHL—— 


PART FIVE. 


CHAPTER 12. 
Section I. 
Il, 

Ill. 
CHapTeR 13. 
Section I. 
II. 

III, 
CHAPTER 14. 
Section I. 
II. 

PART SIX. 


Carrer 15. 
Section I. 
II. 

III. 
APPENDIX A. 


B. 


CONFIDENTIAL 


POLYALPHABETIC SUBSTITUTION SYSTEMS 
PERIODIC POLYALPHABETIC SUBSTITUTION - Paragraph 
Introduction. suclsc tet eed eed iin ee ce pee old acute ee cee ee SESE 12-1 
Theory of solution of periodic polyalphabetic substitution............-.-....---------- 12-6 
Statistical test for determining periodicity.._-..........-------.---------.----------- 12-11 
SOLUTION OF PERIODIC POLYALPHABETIC SUBSTITUTION SYSTEMS 
Systems using standard cipher alphabets......----__.-..-...---. 2222 eee eee 13-1 
Systems using mixed cipher alphabets....._....-....-_._-_- Pela a Oe ese Pia es ace ge eres Dees 13-9 
Special cases and their solution. ..-----...------- 2-2 ee ene 13-17 
INTRODUCTION TO SIMPLE APERIODIC CIPHERS 
Simple aperiodic systems2_--.5. os s2ccsccecet claiewice Disc cewe ve etek eee eceedadex l4-1 
Solution of simple aperiodic systems...__......-.---.-.-------- eee eee eee Li--+ 
INTRODUCTORY CODE SYSTEMS 
CODE SYSTEMS 
Tnitroductionecen 25: fe. crow ea eee ee oe eee ek See eee on pate dete eee cGks 15-1 
Analysis’Of codesssenn Si 2s eves ccs see ed Se noon ewes dat aceon et eiet jieeeeseses 15-5 
Analvsis:of matrix codeSz..c2e222c¢ere0se5..cascee es deere owl saluetedesSeoeossc: 15-9 
FREQUENCY DISTRIBUTIONS OF ENGLISH DIGRAPHS.......-... 2.22 -------- 
FREQUENCY DISTRIBUTIONS OF ENGLISH TRIGRAPHS_._....- 222222222. 
FREQUENCY DISTRIBUTIONS OF ENGLISH TETRAGRAPHS.__.__ 2222 eee 
1 WORD AND. PATTERN LIST Seccctu ek < fetoci tee se abetel awake cee wld ee eek 


ILLUSTRATIONS (U) 


Figure No. Title Page 

1-1 (C) Transposition systems (U)..22- 22 ee ee ee ee ee ee ee eee 1-5 
2-1 (UY) Frequency tabulation 1 (U)____--...._-- 22 ee eee 2-5 
2-2 (U) Frequency tabulation 2 (U)_......-__._-.-.-. 2. 2- eee eee eee ee ne eee 2-5 
2-3 (U) Standard uniliteral frequency distribution (U)___._._-__-_--_-.-..____.--------------------------- 2-6 
2-4 (C) Uniliteral frequency distribution, transposition cipher (U)..............------------------------- 2-7 
2-3 (U) Comparison, standard uniliteral frequency distribution and transposition text (U)_........--..---.- 2-8 
2-6 (C) Uniliteral frequency distribution, monoalphabetie substitution cipher (U)_.-_..-...-----------_.-- 2-8 
2-7 (TU) Comparison, standard uniliteral frequency distribution and monoalphabetic substitution cipher (U)_. 2-9 
2-8 (C) Point of coincidence, normal uniliteral frequency distribution and ciphertext (U)_._-....-...---.---- 2-9 
2-S@ (VU) Comparison, standard uniliteral distribution and reversed standard cipher alphabet (U)__._....._._.- 2-10 
2-9@ (VU) Comparison, standard uniliteral distribution and mixed cipher alphabet (U)_.........-.-.--------- 2-10 
2-10 (C) Expected occurrence of vowels, English plaintext (U)._..........-.----..----------------------- 2-11 
2-11 (C) Expected occurrence of high-frequency consonants, English plaintext (U)_._.....-.._-.-.-.------- 2-11 
2-12 (C) Expected occurrence of medium-frequency consonants, English plaintext (U)__....__.---_--------- 2-11 
2-13 (C) Expected occurrence of low-frequency consonants, English plaintext (U)_._._.....-.-.------------- 2-11 
2-14 (VU) The Lambda (A) test, expected number of blanks, occurring in English plaintext (U)__..-_-.-.----- 2-12 
2-15 (C) The Phi (#) test, tabulation of frequencies (F) of letters (U)_....-..--....--------------- eee 2-12 
2-16 (C) The Phi (@) test, calculation of go (U)_....._-- 2 ee eee ee eee eee eee eee eee 2-12 
3-1 (C) Matrix routes (U)_..-....02- 00 ee ee ee eee 3-2 
3-2 (C) Columnar extraction routes (U)___.....-2 22-21 eee ee ee eee eee 3-2 
3-3 (C) Reversed writing (U)..........-2 2-2-2 ee ee ee eee Sa+ 
3-4 (C) Reversed phonetic writing (U)_.....-- 020.2222 ee ee eee ee eee eee 3-4 
3-5 (C) Plaintext, reversed phonetics (U)_... 2 eee eee eee ee Janek 
3-6 (C) Vertical writing (U).....-_-_...-__2 2 ee ee ne ee ee eee ee eee 3-5 
3-7 (C) Keyed columnar transposition (U)...:...-..-.... 1-2 --- eee eee eee eee ee eee eee eee 3-6 
3-8 (C) Keved columnar transposition with incompletely filled matrix (U)._.._____._-.-..----.-2----.---- 3-7 
8-9 (C) Addition of nulls after encipherment (U).._......._.-....-.-.---------------- eee 3-8 
4-1 (UT) Letter sequence, incompletely filled matrices (U)..._.._-._.--_. . 1-2-2 eee eee eee eee; 4-2 
4-2 (U) Uniliteral frequency distribution, ciphertext (U)___........._-_-.- 22-2 eee eee 4-3 
4-3 (VU) Standard uniliteral frequency distribution (U)_._.._._._..._.-.---.----------------- eee eee eee £3 
4-4 (C) Determination of column length (U)_--...-----.------------ eee ee ee eee 4-7 
4-5 (TU) Transposition ciphertext uniliteral frequency distribution (U)..-.._.._....-2.------------------.. +-10 
4-6 (C) Isolation of columns in ciphertext (U)_......-.-.-2 02-222 eee eee eee eee ee eee +-12 
4~7 (C) Repeated sequences, cipher message A and B (U)____._._____-.._-..- 2-2 eee eee . £-13 
4-8 (C) Stereotypes as repeated sequences (U).._._._._. 1-2 ee eee eee ee 14 
4-9 (C) Row sequences in a progressive key (U).__..._-_..0 2-2 eee eee eee eee +16 
Recovered matrix and ke rove — _ 4-137 

a 5-2l| 

3-21 

5-9) 

cane 

5-1 

= 

6-3! 
b-+ 
G4 
6+ 
6-5 
6-5 
5-6 
6-7 
6-7 
6-8 
6-8 
6-8 
6-8 
6-9 
6-9 

6-9 ¥ 


9~14@ (C) 
9-14@ (C) 
9-15 (C) 
9-16 (C) 
9-17 (C) 
9-18 (C) 
9-19 (C) 
920 (C) 
9-21 (U) 
9-22 (C) 
9-23 (C) 
9-24 (C) 
- 25 (U) 
9-26 (U) 
9-27 (U) 
9-28 (U) 
9-29 (C) 
9-30 (C) 
9-31 (U) 
10-1 (C) 
10-2 (C) 
10-3 (C) 
10-4@ (C) 
10-4@ (C) 


iv 


Encipherment by a direct standard cipher alphabet (U).-......-.------------------------------- 
Encipherment by a reversed standard alphabet (U)___-_-.---_..------------------ bauer ites 
Uniliteral frequency distribution, substitution ciphertext (U)...-_....-------------------------.- 
Identification of ciphertext values by comparison (U)........-.-.------------------------------- 
Solution by completing the plain component, direct standard cipher alphabet (U)_--.--.-.---_---.- 
Solution by completing the plain component, reversed standard cipher alphabet (U)----...-..-----. 
Derivation of mixed sequence by decimation (U)_._...._--__.---------------------------------- 
Decimation, reuse of letters in count (U).-._-......-.-..-----.------------- eee eee e 
Repetitions in decimation as a result of even numbers as interval (U)___.------.----------------- 
Relation of column order to sequence order (U)---.._...------------------------------ eee 
Comparison of sequences (U).. 2-2 2-2 2s- neon ne enn ce neon nen nn meen ess ce meen ewe eee cee se eee eee 
Keyword and alphabetic segments, keyword mixed alphabet GU) . 225 ee ees estat ieusseeweee 2 
Recovery of a decimated alphabet (U)--..-- yee ened Seid ial Ble ot Te LA 8 ace anh tk ot 
Uniliteral frequency distribution, mixed monoalphabetic substitution (U)_--_.--.----------------- 
Ciphertext: work sheet.(CU) i222 noi esene se eeie hie ee he li keiee sect ert ee ese ease eee 
Ciphertext prepared for analysis (U)_...._._-_..--.------------------------------ +--+ ee 
Triliteral frequency distribution (U)__..........-.------------------ eee eee 
Condensed table of repetitions (U).--.__...--_------------------------- 22 ee eee ee 
Vowel consonant relationships (U)___...__..-_..__--.----_---.-----_- eee ee eee eee 
Analysis: of Weas Ep (U)ici. es oc peste eek en cco seed atetet a Seed etn se bees stokes Sots, 
Partially recovered plaintext (U)...-.....--- 2 0 e ee eee ee eee ee ee eee eee eee eee 
Triliteral frequency distribution (U)_.-.-...-....--.--------.--------- ewes ceees- seis sees 
Consonant:line diagram: (U).2.20 ee oc ee ete to eceetl bee eee meee est 
Vowelsequivalent line (GU) 22 usc tees bows cel scleeecle bees ecb eerste eee tee a sacl sie 
Simple biliteral substitution systems (U)-____-.--.-..---------------------------------------- 
Artificial ‘codé language matrix. (U)..22- 0.2 .ussle ceceesekoadceccna ee nelebs oe eteesece cesses eked 
Multiliteral systems with variants (U)..........--.-------.---------------- ee ee eee 
Preliminary matrix with row and column indicators (U)_.-..._._..-.--------------------------- 
Ciphertext prepared for analysis (U)..._..-.-..---------------------------- ee ee een ee 
Insertion of plaintext values (U)__.________.___...---.---- ee eee eee eee 
Solution: of matrix: CU) <22222. 2. cscolcc Sues sbcccccose wees Peewee Sete sestew ego se se Sa he 
Preparation of ciphertext for digraphic frequency distribution (U)..--...-...-..------------------- 
Digraphie frequency distribution (U)....._....-.--------.----------------- oe eee 
Match-of rows A.and)B((U)suci cnc cc eho oe occa te ede dives Vo estene secs eee 
Matching rows N and O inserted (U).-_____...-.------------- +. eee ee eee eee eee 
Possible matches of row E (U)....-.------- ee en nn ee nn nn nn nn nee 
Completion of row matches (U)_._.____..-..-.--- -_ ee eee ee ee eee 
Matrix with both rows and columns matched (U)_.___...-___-___._-___-_----------------------- 
Digraphiec frequency distribution, message A (U)_..---..._-_.-_._------------------------------- 
Digraphie frequency distribution, message B (U)...._.__.......-------------------------------- 
Superimposition of messages A and B (U)_.__..______.__-..-.-.---_-.-----_------------------- 
Chain: of equal: values (U).52 202 0 os oso) het ectece elie eect ctohose chee soe e eee Sass 
Reconstructed matrix (U).......--.. 2. 2 e eee ee ee ee eee eee 
Recovered: matrix: (U).2.2oucceadin cde deseo cc eee coe e So ue Jee oe Seeec ewes ie 
Columner numeric system (U)_..-___-- ee ee eee ne ee eee eee eee 
Encipherment using the columnar numeric system (U)_.........--------------------------+------ 
Four-part dinomic frequency distribution (U).....______...-....------------------------------- 
Monome-dinome system (U)_______.-_------- oe eee en ne eee eee eee 
Ciphertext and monomic frequency distribution (U)_._........-..---.--------------------------- 
Cipher message and monomic frequency distribution (U)_....__....----------------------------- 
Initial placement on column indicator (U)..-....--.-...-_-.-.------------------- eee 
Expansion of-matrix: (UO). o ae Shot ee eek es i bode eed ee eee tee cae 
Second expansion of row and column indicators (U)_....-....._...-_..----------------------+-- 
Final: reconstructed form: ((U) 2.20 22 oe oo ewe ee ee coe Soke Deedee eee cee seo see 
Example of monome-dinome-trinome system (U)...........-....------------------------------- 
Trinomic-system.-(U) = b.c52cco05 a elit oe ete wo Beetle eee eee hee ee. 
Reconstructed ‘matrix: (WU) 2-25 eed s asc gee soon beset cine eee seceenceceede dee wceteecuae sels 
Reciprocal ‘cipher table.\(U) oso eos eee sce ese le ese ede Secceh ec toeeu el est eel eee cece. 
Nonreciprocal:cipher table: (U)i. 5 csi oon oct ied Che cusedews sca cevcewe uae wou teb senescence 
Pour-square matrix: (U)sie. oS knee elec co cee sSoue ee ccbeocceeetec lt ecacgecs see ecteeeedewes 
Enciphering operation, four-square matrix (U).._._._...__.--.------------- eneeeeeee eeee 
Deciphering operation, four-square matrix (U)-.._..-.-----.-.------------- ee eee eee eee 


CONFIDENFIAL_ 


Figure No. 
10-5 (C) 
10-6 (C) 
10-7 (C) 
10-8 (U) 
11-1 (U) 
11-2@ (C) 
11-2@ (C) 
11-3 (C) 
11-4 (C) 
11-5 (C) 
11-6 (C) 
11-7 (C) 
11-8 (C) 
11-9 (C) 
11-10@ (C) 
11-10@ (C) 
11-11 (C) 
11-12 (0) 
11-13 (U) 
11-14@ (C) 
11-14@ (C) 
11-15 (C) 
11-16 (C) 
11-17 (C) 
11-18 (C) 
11-19 (C) 
11-20 (C) 
11-21 (C) 
11-22 (C) 
11-23 (C) 
11-24 (C) 
11-25 (U) 
11-26 (C) 
11-27@ (C) 
11~27@ (C) 
11-28 (C) 
11-29 (C) 
11-30 (C) 
11-31 (C) 
11-32 (C) 
11-33 (C) 
11-34 (C) 
11-35 (C) 
11-36 (C) 
11-37 (C) 
11-38 (C) 
21-39 (C) 
11-40 (C) 
12-1 (C) 
12-2 (C) 
12-3 (C) 
12-4 (C) 
12-5 (C) 
12-6 (C) 
12-7 (C) 
12-8 (C) 
12-9 (C) 
12-10 (C) 
13-1 (C) 
13-2 (C) 
13~3 (C) 
13-4 (C) 
13-5 (C) 
13-6 (C) 
13-7 (C) 
13-8 (C) 


CONFIDENTIAL 


Horizontal two-square matrix (U)_..-_-.-.--------------------------------------------------- 
Vertical two-square matrix (U)..._...-----..--.--------+--------------------------- 22 e eee 
Numeric variation, four-square matrix (U)_..........-------------------------------- eee 
Digraphic Lambda (A) test (U)_.--_.--------.------------------ +--+ - 2-2 eee eee eee 
Uniliteral frequency distribution, four-square cipher (U)--....---------------------------------- 
Ciphertext prepared for analysis (U)...--_.....---------------------------------------------- 
Digraphic frequency distribution (U)._..-_.._.-.--------------------------------------------- 
Assumed plain component, four-square matrix (U)__.------------.--------------+-----------_--- 
Insertion. of cipher values: (U)u2.222<2205.-- 525 3e ee se seu eee eee ee eb Soe ee cee ee ecbcaed 
Placement of cipher values by assumption of sequence (U).-__.---..__-------------------------- 
First partial reconstruction of plaintext (U)_.-..-----------------.---------------------- eee 
Test of cipher value placement (U)_....----------------------------+-------------- eee 
Second partial reconstruction of plaintext (U)__..-..------------------------------+------------ 
Insertion of cipher values through analysis (U)_--...--.---.--_----------------------- +e 
Partially recovered four-square matrix (U)_...-.------------------------------- ee eee eee 
Partially recovered plaintext (U)........-.------------------------------------------------ eee 
Ciphertext for analysis: (UW) 225 22 .s2s2sVoos. 2253 esse de et deeee fot ee tee ee eee oe See ee, 
Digraphic frequency matrix (U)----------------------------------------------- eee eee 
Test for probability of transparencies (U).-..---.---.------------------------------- eee eee 
Possible transparencies from ciphertext (U)----.----------------.-------- ene ee eee eee 
Possible transparencies reversed (U)_------------------------------------- eee eee eee eee 
Preliminary reconstruction matrix (U)..--.-...----------------------------------- ee eee 
Analysis of cipher-plain value location (U)__-_.---------.-----------.------------------------- 
First expansion of reconstruction matrix (U)___-__-__--...._------------------------------------- 
Second expansion of reconstruction matrix (U)-.._........-------.-...------------------------- 
Rearrangement and expansion of reconstruction matrix (U)___.-....._.-------.------------------ 
Third expansion of reconstruction matrix (U)_....__..----..-----..---------~------------------ 
Initial construction of two-square matrix (U)...._._------------------------- eee eee 
Rearrangement of square P2-C1l (U)-__-.......__---------------------- eee ee ee ee eeeeee 
Rearrangement of square P1-C2 (U).___...... etek tohoce eet ate se Seek le ee 
Partially recovered horizontal two-square matrix (U)_._.___.-----------.----------------------- 
Example Playfair'square: (U) 122 222222522252 cece sceols deel ete esse bee sncueesecos yess esse 
Reciprocal, reversible relationships (U).._--_-__- ne Sot eet ees he Sn ee pats ous ee 2 Lier i 
Ciphertext prepared for analysis (U)___-_._..__._____-2-----------2 +--+ eee eee 
Digraphic frequency distribution Playfair cipher (U)_.-..--.-----.------------------- Set) ae nik 
Use of rule 1 to determine plaintext values (U)_..__-.-.---.----------------------------------- 
Construction of preliminary matrix (U)......._..-.---------------------------------- ---e- 
First expansion of matrix (U)_....-... 20222 ee ee nn nn ewe en eee ee ene eee eee 


Recovery of mixed keyword sequence (U)_..........____----_-------------- eee ----- == -- 
Matrix permutation (U)_-_._.....----0.0 20.0 eee ee eee eee eee 
Repetition of column permutations (U)_...... .._...__...-.-_------------------------ +--+ -- 
Selection of current permutation (U)____._.. 4 catentthns steel retard h SAS Cte fe oS os eye eee ae 
Recovery of keyword mixed sequence and original enciphering matrix (U).........---------------- 
Example, polyalphabetic substitution (U).... 000 _._._-_e eee eee eee eee eee eee - 
Columnar encipherment duplicating key period (U).__.___._______..---------.----------------- 
Table of expected polygraphs (U)_.__....... ge Dh te ia i Ned ee at Bs Bt Nt a Ee Rar ras Maid 
Ciphertext with evidence of periodicity (U)...........0-.2--- eee eee eee eee eee eee eee 
List of repetitions and factors (U)_..---.....00 6. oe eee ee eee eee ee eee eee eee 
The ¢ test for factored periods (U)...-........0 ©... eee eee eee eee eee eee 
Index of coincidence for factored periods (U)_....  __.______------------------- eee eee ee eee 
Expected values of ¢ and ¢, (U)_-....-..... ©0022 eee ee ee eee 
Computation of $, long periodic key (U)_.... wate 2 per nt en edie a ars Masa sath AS cree ae 
¢ long periodic key computation (U)__._......._......--- 22 e eee ee eee 


‘Ciphertext prepared for analysis (U)___.._.........----- eee eee eee eee eee eee eee eee 


Uniliteral frequency distribution of ciphertext on period of five (U)_._-.._.---...--.------------- 
Recovered enciphering matrix (U)_.._.____..__-- 2-2 ee eee ee ee eee ee ene 
Completion of the plain component (U)___.___....-------------- eee e ee een ee eee nee 
Completion of the plain component, text arranged by period (U)___........---------------------- 
Generatrix identification (U)___........._._.__ 22 ee eee eee 
Generatrix identification using arbitrary values (U)____....--------.--------------------- 
Location of probable word (U)__.-._._...__..--- oe eee nee ne ee ee ee eee 


CONFIDENTIAL 


Figure No. Title Page 
13-9 (C) Key derivation (U).....--------------------- 2 oo ee enn een ee eee 13-8 
13-10 (C) Key derivation, step 2 (U)__------------------------ee eneeneeeeee 13-8 
18-11 (C) Case II secondary alphabets (U)------.-..-. enna eee eee eee eee eee 13-9 
13-12 (C) Letter placement, direct symmetry of position (U)_._--...--.---.--- eee 13-9 
138~13 (C) Placement transfer, direct symmetry of position (U).--.---------.------.----------------- Lee 13-10 
13-14 (C) Placement transfer (U)_-_.-------.---------------------+--- +--+ eee eee 13-10 
18-15 (C) Ciphertext prepared for analysis (U)._..--.--_----------------------------------------eeeee 13-10 
13-16 (C) Determination of period (U)----.--------------------------------- eee ee 13-10 
13-17 (U) Uniliteral frequency distribution, alphabet 1 (U).._------.------------------- eee ee 13-11 
13-18@ (C)  Triliteral frequency distribution, alphabet 1 (U)-----------.-~---.------------- ee 13-1] 
13-18@ (C) Triliteral frequency distribution, alphabet 2 (U)_...-----------------------a eee 13-12 
13-18@ (C) Triliteral frequency distribution, alphabet 3 (U)_.--.-..-.------------------ eee 13-12 
13-18@ (C) Triliteral frequency distribution, alphabet 4 (U)_..--..--.---.---------------- ee eee eee 13-12 
13-18® (C) Triliteral frequency distribution, alphabet 5 (U)____.---.----.--.-------- 2 ee eee 13-13 
13-19 (C) Condensed table of repetitions (U)_...---.-_--------------------------- ee eee eee 13-13 
13-20 (C) Identification of cipher to plain equivalencies (U)_-_.------------------------- eee ee 13-14 
13-21 (C) Identification of vowels and consonants (U)__._---_-.----.--------- eee eee eee eee 13-14" 
13-22 (C)- Reconstruction matrix (U)--..--------.-.---.-------- ee en ee eee 13-15 
13-23 (C) Recovered value transfer (U)-.---..-----.--------------- oe ee ee ee eee 13-15 
13-24 (C) Additional value placement (U)__..._._-.-.-.-.---------~---------- ee eeeeeeeeeeeeee 13-15 
13-25 (C) Partially recovered plaintext (U)_-_--_----.---.-------------- eee eee 13-16 
138-26 (C) Insertion of recovered values (U).-_._.-..---_-----.----- ee eee ee ee ee eee 13-17 
13-27 (C) Insertion of recovered values, step 2 (U)___..-_.-.----.------------------- en eee 13-17 
13-28 (C) Expansion of matrix (C).--------------------------------- ee ee eee ee eee eee 13-17 
13-29 (C) Plaintext partially recovered (U)_-....-__.--.------------------------- ee ee ee eee eee 13-18 
13-30 (C) © Ciphertext for analysis (U).-.._.__._----..-...--------------------- ee ne ee eee 13-19 
13-31 (C) Rough scoring of generatrices (U)...____.____-------.---------------- eee eee eee eee 13-20 
13-32 (C) Uniliteral frequency distribution, secondary cipher sequences (U)..---_-_-------------.-.------- 13-22 
13-33 (C) Matching by cyclic shifting (U)...._.__.-___-.-.-.------------------------- 2 eee 13-23 
13-34 (C) Ciphertext reduced to monoalphabetic terms (U)_.....-------------.--------------------------- 13-23 
13-35 (U) Uniliteral frequency distribution of monoalphabetie terms (U)_......-..------..----._----------- 13-24 
13-36 (C) Period determination (U)_-..........-..-..--.-------- =~ nn ne ee eee ee 13—24 
138-37 (C) Uniliteral frequency distribution of periodic cipher alphabets (U)_....-.----.--.-.--------------- 1325 
13-38 (C) Possible matches, periodic cipher alphabet 1 and 2 (U)__--.----..-------------------- pee ene n-ne 13-25 
13-39 (C) Final match of periodic cipher alphabets (U)..........-.------2--------2--- eee eee 13-25 
13-40 (C) Ciphertext reduced to monoalphabetic terms (U)_..-.....-------------------------------------- 13-26 
13-41 (U) Uniliteral frequency distribution of monoalphabetic terms (U)_...-.-------------.--------------- 13-26 
138-42 (C) Solution of ciphertext (U)__.---..-.-.-.---.--------- 2 - =e ee nen ene nn ne ee ne 13-27 
13~43 (C) Recovered matrix (U)__.-.-------------- + - eee 13-27 
14-1 (C) Encipherment by arbitrary group length (U)__._...-.---.-.-.-------------.---.---------- + --- 14-2 
14-2 (C) Numerically keyed encipherment, standard alphabets (U)-.-.-.-.-.----------------------------- 14-4 

° 14-3 (C) Aperiodic cipher message (U)_.._...._-.-.._-__._-.-.--------- eee eee eee 14-4 
14-4 (C) Expansion of matrix (U)..__..-..-----.-...-.-.--------- 2-2 oe eee eee 14-5 
14-5 (C) Matrix reduction (U)...._.--.--------- ee ne ne ne 14-6 
14-6 (C) Partial matrix and recoveries of plaintext (U)...._....--..--.----------------- eee ee eee 14-7 
14-7 (C) Insertion of cipher values (U)____._.._..- 2 2 ee eee 14-7 
14-8 (C) Transcription of matrix (U)._.__.-.....-2- 2-1 eee ee ee eee 14-8 
14-9 (C) Recovered matrix (U)__....- 2-2-2 ne eee 14-8 
14-10 (C) Idiomorphs formed in encipherment (U)_..____._....-..-..-.---------.------- eee 14-10 
14-11 (C) Frequency distribution columns 1-10 (U)._..._.___-.-------.--------e e ee eeeee eee 14-11 
14-12 (C) Plain letter as interrupter (U)__...........------ 2 eee ee ee eee eee 14-12 
14-13 (C) Cipher letter as interrupter (U).__._._.....-..-.-- 2 eee eee eee eee lee) 1418 
14-14 (C) Repetitions as a result of interrupter letter encipherment (U)___._....-.-.---.-.----------------- 14-14 
14-15 (C) Frequency distribution and polygraphs of superimposed columns (U)__-_-.-.-.----- Lene e een eee 1415 
14-16 (C) Initial placement of value (U)__...._--_--__- eee eee eee eee eee ee eee 14-16 
14-17 (C) Completion of assumed sequences (U)_._.___- ee ee ee eee 14-16 
14~18 (C) Insertion of plaintext values (U)._.._..._._.--...--.-...- ee ene 14-16 
14-19 (C) Completion of matrix (U)_____.._....2.-2 2 ee ee eee 14-18 
15-1 (C) Two part code (U)-_.-. a eee 15-2 
15-2 (C) Matrix code (U).-..-. 2 i eee nee 15-3 
15-3 (C) Upper case, lower case, matrix code (U)___.._____.------- += ee ee ee ee eee 15-4 
15-4 (C) Syllabary square (U).______.- 2-202 ee ene 15-4 
15-5 (C) Operator’s code (U)____. oe ee ee eee 15-5 
15-6 (C) Arithmetic enciphered codes (U)_._._...-2 02-2 ee ee ee ee ee ee eee 15-6 
15-7 (U) 10 x 10 matrix, single digit coordinates (U)__.._..-.- 2-3 ee eee ee ee eee 15-8 
15-8 (U) 10 x 10 matrix, dinome coordinates (U).__._....._...-.----.-- 2-2 eee eee 15-8 
15-9 (C) Idiomorphism in code sequences (U)._______-_.--------1------ eee eee eee eee ene ee 15-10 


A-8 (C) 
A~9 (C) 
A-10 (C) 
B-1 (C) 
B-2 (C) 
B-3 (C) 
B-4 (C) 
| C-1 (C) 
C-2 (C) 


C-3 (C) 


C-4 (C) 
C-5 (C) 


D-1 (C) 
D~2 (C) 


D-3 (C) 
D~4 (C) 


LIST OF TABLES (U) 


Frequency distribution of digraphs (U)_..........------.--------.------ oe e eee eee eee 
The 428 digraphs of Table A~1, arranged according to their absolute frequencies, accompanied by the 
logarithms of their assigned probabilities (U)_----------------.--_---__---------------------- 
The 18 digraphs composing 25% of the digraphs in Table A-1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically according to their initial letters (U)_..----..------ 
The 53 digraphs composing 50% of the digraphs of Table A-1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically according to their initial letters (U)___--_---_------ 
The 122 digraphs composing 75% of the digraphs of Table A-1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically according to their initial letters (U)_.---.---.----- 
The 428 digraphs of Table A-1, arranged in alphabetic order by initial letters, then by absolute 
frequencies accompanied by the logarithms of their assigned probabilities (U)_...--.------------ 
The 428 digraphs of Table A~1, arranged in aiphabetic order by final letters, then by absolute frequency, 
accompanied by the logarithms of their assigned probabilities (U)___...____.-.--------------+-- 
The 18 digraphs composing 25% of the digraphs of Table A~1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically by final letters (U)_.......-.-------------------- 
The 53 digraphs composing 50% of the digraphs of Table A-1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically by final letters (U)......------------------------ 
The 122 digraphs composing 75% of the digraphs of Table A-1, accompanied by the logarithms of their 
assigned probabilities, arranged alphabetically by final letters (U)_.--.------------------------- 
The 56 trigraphs appearing 100 or more times, arranged according to their absolute frequencies, ac- 
companied by the logarithms of their assigned probabilities (U)_-_.--_------------------------- 
The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by initial letters, then by 
absolute frequencies, accompanied by the logarithms of their assigned probabilities (U)__.-.--.--- 
The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by central letters, then by 
absolute frequencies, accompanied by the logarithms of their assigned probabilities (U)_----.1_--- 
The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by final letters, then by 
absolute frequencies, accompanied by the logarithms of their assigned probabilities (U)----.------ 
The 54 tetragraphs appearing 50 or more times arranged by absolute frequencies, accompanied by the 
logarithms of assigned probabilities (U)__.......____-_-.......-------_----------------------- 
The 54 tetragraphs appearing 50 or more times arranged in alphabetic order by initial letters, then 
by absolute frequencies accompanied by the logarithms of assigned probabilities (U)__-----.--.--- 
The 54 tetragraphs appearing 50 or more times arranged in alphabetic order by their second letters, 
and then according to their absolute frequencies, accompanied by the logarithms of their assigned 
probabilities CU) 2.0.2.2 eee ee eM ook cede sok ids Cocca detocae 
The 54 tetragraphs appearing 50 or more times arranged in alphabetic order by their third letters, 
then by absolute frequencies, accompanied by the logarithms of their probabilities (U)___--------- 
The 54 tetragraphs appearing 50 or more times arranged in alphabetic order by their final letters, then 
by absolute frequencies, accompanied by the logarithms of their assigned probabilities (U)-~------ 
List of words used in military text arranged alphabetically according to word length (U)_____-..-_-- 
List of words used in military text arranged alphabetically in reverse order according to word length 
CU) gt otk oN AU Aas eee et te a Sete yl ate ee et Se sacar Soca eee essa eatie toe as 
List of words used in military text arranged alphabetically according to word pattern (U)___----.--- 
List of general digraphic idiomorphs (U)_____._.___---------------------- eee ee eee 
List of Playfair digraphic idiomorphs (U)_..........._...-.----------------------------------- 
List of four-square digraphic idiomorphs (U)...._._......_.------------------------------------ 
List of words containing like letters repeated at various intervals (U)-._..._._-.----------------- 
Expected number of repetitions, polyalphabetic ciphers (U)_._._....-.-.---.-..------------+----- 
Expected values of ¢, and ¢, (U) 
actor table (0): 2a. cet oe ene At oot en OG Sd hades The eee eens Bune ia a el, ee BAe MEE, Bie Batt 
Table of primes up to 2000 (U) 


vii 


CONFIDENTIAL 


CONFIDENTIAL 


PART ONE (C) 
INTRODUCTION TO CRYPTANALYTICS 


CHAPTER 1 (C) 
INTRODUCTION 


Section I. (U) GENERAL 


1-1. (U) Purpose 

This manual presents the basic principles of cryptana- 
lytics and its relation to cryptography. Cryptography 
deals with the art of secret communications while 
cryptanalytics treats of their solution by those who 
do not have access to the plaintext communications. 
The manual is primarily a training text, designed to 
promote an understanding of the practical applica- 
tion of cryptanalytics to provide the student with 
the knowledge of the techniques and methods used 
.in the cryptanalysis of common codes and ciphers. 


1-2. (U) Scope 

This manual has been organized into six parts. The 
first part deals with the fundamentals necessary to 
study the remaining five parts. In each subsequent 
part, the manual covers a type cryptographic system, 
its practical application, and the appropriate analysis 
methods. The material presented in each part 
represents a more complex cryptographic svstem 
than that preceding it and, therefore, requires a more 
detailed study. All parts except the last two are 
thorough in the scope of their study. The last two, 
due to the extreme difficulty of the subject matter, 
have been limited to an introductory study only. 
Note at the outset that each system presented has 
many possible variations. All the variants have not 
been included. The contents have been deliberately 
limited to those systems, methods, and techniques 
which offer the broadest possible application, and 
which, when mastered, will provide the greatest 
degree of understanding of the subject area. 


1-3. (U) Changes or Revisions 


Users of this publication are encouraged to submit 
recommended changes and comments to improve the 


publication. Comments should be keyed to the 
specific page, paragraph, and line of the text in which 
the change is recommended. Reasons will be provided 
for each comment to insure understanding and 
complete evaluation. Comments should be prepared 
using DA Form 2028 (Recommended Changes to 
Publications) and forwarded direct to the Command- 
ing General, United States Army Security Agency, 
ATTN: IAFOR-RL, Arlington Hall Station, Arling- 
ton, Va. 22212. 


1-4. (U) Developments 

Cryptology, the branch of knowledge which treats of 
the principles of cryptography and cryptanalytics, 
is not a static art or science. Constant change, both 
in the systems used and in techniques of analysis, 
is its hallmark. What is regarded today as un- 
necessary, or as wholly impractical, may become 
possible and absolutely necessary tomorrow. The 
development of cryptology has a long history. Basic 
systems of cryptography and of cryptanalysis devel- 
oped in the past, although relatively simple by 
today’s standards, still are applicable. In some cases 
these same systems and techniques, or variations of 
them, are still in use today. These systems vary, from 
the relatively simple hand-generated ciphers and 
codes to the highly sophisticated and complex 
machine systems. Accordingly, the methods and 
techniques of their solution also vary from rather 
simple methods to highly involved studies requiring 
a great deal of time and skill. However, the basic 
techniques used in the solution of the less complex 
systems form the basis for the study and the analysis 
of the more complex systems. For this reason the 
following text progresses from the simple through the 
more complex. 


GONFIDENTIAL— | 14 


GONFIDENFHIAL— 


ee 


Section Il. (C) TERMINOLOGY 


1-5. (U) Basic Definitions 

In cryptology, as in any other art or science, a host 
of words and phrases exist, each having special 
meanings within the context of the subject area. 
These meanings may or may not relate to the common 
usage of the word or phrase. As forms of verbal short- 
hand, it is invaluable to state exactly what is meant 
with the minimum use of time and words. For the 
purpose of this manual it is necessary to understand 
some of the common definitions at the outset. Other 
definitions will be introduced and explained in detail 
as the subject is presented. For a complete list of 
definitions the NSA Basic Cryptologic Glossary, 
1965, may be consulted. 

a. Signal Communications. Any means of trans- 
mitting messages other than by direct conversation 
or mail. A commander uses signal communications 
to receive reports of hostile dispositions and activities, 
to receive reports of the progress and needs of sub- 
ordinate and neighboring friendly units, to send 
orders to subordinate units, to receive orders from 
superior units, and to send to higher and adjacent 
units information necessary for the coordinated action 
of the whole command. 

b. Means of Signal Communications. A medium, 
including equipment, used by a command for trans- 
mitting and receiving messages. The most important 
are: ; 

(1) Wire. 
(a) Telephone. 
(6) Telegraph. 
(c) Teletypewriter. 
(d) Facsimile. 
(2) Radio. 
(a) Radiotelephone. 
(b) Radiotelegraph. 
(c) Radio teletypewriter. 
(d) Radio facsimile. 

c. Message Center. A communications facility, sub- 
ordinate to and usually located within or nearby a 
command, having one or more of the above means 
of communications available. It serves as a point of 
origin, destination, and relay for messages within the 
command. Here messages are processed prior to 
transmission and after reception. 

d. Writer. The person who actually prepares and 
signs the message. The writer may be the originator 
or his officially designated representative. 

e. Originator. The command by whose authority a 
message is sent. A commander may delegate this 
authority to one or more subordinates, who originate 
messages as required in the commander’s name. 


jf. Addressee. The office, headquarters, activity or 
individual to whom a message is directed by the 
originator. 

g. Externals. Those elements appearing outside 
the body of the message placed on the message by 
the communications center for the purpose of 
routing. Examples of externals are callsigns, serial 
numbers, precedence indicators, times of file, and 
special routing instructions. 

h. Message Text. That portion of a message which 
contains the communication. It may be in plain- 
text or in secret writing. 


1-6. (Q) Secret Communications 

a. Intercommunications are any means susceptible 
to interpretation by one of the five senses. Those 
most commonly used are visual or auditory. Aside 
from the use of simple visual and auditory signals 
for intercommunication over relatively short clis- 
tances, military communications depend upon the 
act of writing (messages), speaking (telephone and 
radiotelephone), and projecting a picture or illus- 
tration (TV and facsimile). Of these methods, our 
interest lies primarily with the first, and the latter 
two only insofar as the transmission of. messages are 


concerned. 


b. The origins and use of secret communications 
are unknown, but probably began in some form 
with man’s ability to communicate. They originated 
in the earliest days of organized warfare and diplo- 
matic relations where they were soon recognized as 
a necessity. The earliest reliable reference to the 
use of secret writing occurred in 900 A.D. when 
Plutarch reported the ancient Spartans as using a 
device called Scytale, a method of secret writing in 


- which a narrow strip of parchment was wound round 


a wooden baton, the message written across the 
adjoining edges. History records the subsequent 
growth of the art, but the real beginnings of sys- 
tematic modern cryptology is traced back to the 
early 13th century. During this period the science 
was developed and employed extensively in the 


‘diplomatic relations of the Papal States. From this 


period forward, its growth, although sporadic, has 
been constant. Systems of greater complexity have 
been introduced followed by the development of 
methods and techniques for their analysis. 

c. Speech can be secured by electronic devices 
that distort, substitute, or change the electrical 
current of telephone and radiotelephone, rendering 
it unintelligible to all but those provided with 
similar electronic devices properly arranged for the 
purpose. The same thing is true in the case of 


1-2 CONFIDENTIAL 


CONFIDENTIAL 


facsimile transmission (the transmission of charts, 
maps, illustrations, messages, etc.), and simple 
forms of enciphered television transmissions cur- 
rently used in conjunction with “pay-TV.” In both 
instances, lacking the proper device to decipher the 
signal, one would be unable to receive intelligible 
information. . 

d. Writing can be secured by two general methods. 
It can be made invisible or unintelligible. 

(1) Invisible writing is done with certain chem- 
icals called invisible, sympathetic, or secret inks 
which are invisible to the naked eye. In order to 
make the writing visible, the message is first processed 
with a suitable reagent which in effect develops the 
message. Invisible writing is also produced by reduc- 
ing the writing to microscopic size. This method 
requires special photographic equipment to reduce 
the writing, and later enlarge the writing to make 
it visible. 

(2) Although invisible writing finds some appli- 
cation in military communications, by far the most 
important means of producing secret writing is by a 
cryptographic process, a far simpler and more effec- 
tive method. The writing remains visible but its 
secrecy is protected by its unintelligibility. 


1-7. oa Plaintext and Encrypted Text 


a. Visible writing which is intelligible, i.e. conveys 
an understandable or sensible meaning (in the 


language in which it was written) and does not intend 
to convey a hidden meaning is plaintext. A message 
in plaintext is termed a plaintext message, a cleartext 
message, or sometimes a message in the clear. 

b. Visible writing which conveys no intelligible 
meaning in any recognized language is in encrypted 
text, and such writing is a cryptogram. 

ce. Visible writing may be intelligible, but the 
obvious meaning it conveys may not be the real 
meaning intended. Secret communications of this 
sort are impractical for field military use but are 
often encountered in espionage and counterespionage 
activities. 


1-8. (S&F Plain and Cipher Alphabets 

a. A plain alphabet is a series of symbols constitut- 
ing. the speech sounds of a language, arranged in 
their normal sequence. A cipher alphabet is one in 
which the same elementary speech sounds are repre- 
sented by symbols other than those used in the 
normal alphabet. A cipher alphabet is composed of 
two components, the plain component represented 
by a plain alphabet, and a cipher component, repre- 
sented by a disarranged alphabetic sequence. 

b. Basically the method of using a cipher alphabet 
involves finding a plaintext value in the plain com- 
ponent and then finding the cipher value which is © 
substituted for it in the cipher component. 


Section Ill. (27 CRYPTOGRAPHIC SYSTEMS 


1-9. (DB Codes, Ciphers, and Enciphered Codes 


A general cryptographic system is the sum total of 
all the basic invariable rules followed in converting 
the plaintext of a message to ciphertext, producing a 
cryptogram, and the reverse, drawn up between 
correspondents or furnished them by higher authority. 
All cryptographic systems can be classed in two basic 
systems, or one variation, according to the treatment 
the plaintext undergoes in its transformation to a 
cryptogram. The two basic systems are cipher systems 
and code systems. 

a. In ciphers or cipher systems, cryptograms are 
produced by applying the cryptographic treatment 
(process whereby plain writing is changed to secret 
writing) to individual letters, or groups of individual 
letters, of the plaintext message. A cryptogram pro- 
duced by this method is in cipher, and is called a 
cipher message or a cipher. The operation is called 
enciphering. Changing the cipher into plaintext is 
called deciphering. A cipher message may be pro- 
duced - by several processes. A cipher table, cipher 
device, or cipher machine may be used for the en- 
cipherment of a message. Any of the cipher systems 


involving only the use of paper and pencil are known 
as cipher tables. A cipher device is an apparatus or a 
simple machine for literal encipherment and de- 
cipherment, usually; manually operated. A cipher 
machine is a more complex electromechanical device 
serving the same purpose but usually requiring an 
outside power source. It may be operated ‘‘off line” 
whereby a cryptogram is produced privr to trans- 
mission, or it may be operated ‘‘on line’ whereby 
the process of encipherment-transmission-decipher- 
ment occurs simultaneously between correspondents. 
b. In codes, or code systems, cryptograms are pro- 
duced by applying the cryptographic treatment to 
entire words, phrases, or sentences of the plaintext 
message. A characteristic of codes is that the crypto-. 
graphic element used as replacement of the plain-— 
text elements is normally of constant length as 
opposed to the replaced plaintext element which 
varies in length. A cryptogram produced by means of 
a code system is called a code message, or more simply 
a code, the text being referred to as code text. Pro- 
ducing a cryptogram is called encoding. Breaking the 
code back into plaintext is called decoding. A code 


CONFIDENTIAL — 3 


CONFIDENTIAL 


message may be produced through the use of several 
types of code systems. Common systems include code 
books, code charts, and code tables. All code systems 
are manually operated and are composed of listings 
of plaintext and corresponding cipher values. The 
foregoing classification of code systems is based on 
the manner in which the values are listed. 

c. The variant class of systems previously men- 
tioned are not encountered as often as the basic 
types, although still important. This class contains 
such quasi-systems as enciphered codes, systems 
where code groups are enciphered; encoded ciphers, 
systems wherein ciphertext is encoded; and super- 
encipherment, systems wherein ciphertext is again 
enciphered in another cipher system different from 
that used to produce the original ciphertext. The 
complexity of these processes, the amount of time 
needed, the possibility of inducing errors, and the 
problematic increase of security created by these 
methods are factors which limit their use in most 
military communications. 


1-10. 6 Discriminants (System Indicators) and 
Specific Keys 

Cryptographic systems, regardless of type, normally 
include two elements, not part of the plaintext, to 
facilitate processing and handling. The elements 
may be a single number, a single letter, a group of 
letters or numbers, or a word or a phrase. The ele- 
ments usually correspond in structure and external 
appearance to the cipher or code text in order to 
conceal them. However, to aid in their recognition 
by communications center personnel, they usually 
occur in a specific position within the text of a 
message. These two elements are the discriminant, 
or the system indicator, and the specific key. 

a. The discriminant indicates the specific crypto- 
graphic system used to produce the cryptogram. 

b. The specific key, used in conjunction with the 
discriminant, indicates “how” the cryptographic 
system was used. It may indicate the starting point 
in code books and manual cipher systems, the ‘‘set 
up” for a cipher machine or device, the manner in 


which the machine is prepared for the encipherment 
and decipherment of a specific message. The specific 
key is changed frequently, after a given number of 
characters have been enciphered, at the end of a 
time period, or after a message. Exact periods of 
usage of a given key may be dictated by higher 
authority or by agreement among correspondents. 
Derivation of specific keys involves the use of spe- 
cially prepared tables, documents, or books. 


1-11. oo Ciphers, Transposition and Substitution 


The two distinct types of cipher treatment, applied 
to plaintext to covert it to secret text, yield two 
different classes of cryptograms. In the first, trans- 
position, the elements or units of the plaintext retain 
their original identity and only undergo a change in 
their relative position. In the second, substitution, 
a cipher element of varying length is substituted for 
a plaintext value, usually of the same length. More- 
over all cipher elements within a given system are 
normally of the same length, though there are a few 
exceptions. 

a. A simple form of a transposition cipher may be 
observed in figure 1-1. As the system’s name implies, 
ciphertext is generated simply by the disarrange- 
ment of the letters of the plaintext. But note, this 
disarrangement is not a random process, rather it 
follows specific rules. In this case the plaintext is 
inscribed in the cells of a matrix as one would 
normally write, then extracted by columns from left 
to right and put into groups of five letters to form 
ciphertext. 

b. The second class of treatment by which a 
written plaintext message can be converted to secret 
text is by substitution. In substitution systems, the 
elements of the plaintext retain their original relative 
positions to one another, but are replaced by other 
elements which have different values or meanings, 
with the result that the original text becomes un- 
intelligible. A simple example of such a substitution 
system is one used by General Clinton during the 
American Revolution: 


ABCDEFGHUKLMNOPQRS TUVWX Y Z 
51 52 53 54 55 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 7S 


Using this system, a message was enciphered by 
substituting two numerical values for each literal 


value in the plaintext message. For example, the fol- 
lowing message would be enciphered as shown below: 


GEN B ARNOLD AT WEST POINT 
616567 52 517167686554 51738 75557273 6968636773 


1-4 CONFIDENTIAL 


INSCRIPTION ROUTE 


PLAIN TEXT 


TRANSPOSITION CIPHER SYSTEM 


TRANSCRIPTION ROUTE 


CIPHER TEXT 


IPIPY ROOHS ASNET NICRE STISM 


Figure 1-1 ra Transposition systems (U). 


1-12. (& Divisions of Cipher Systems 


Each of the two classes of cipher systems, trans- 
position and substitution, are further subdivided 
based on the number of characters composing the 
textual elements of units undergoing treatment, and 
the number of cipher elements replacing the plaintext 
elements. A sharp line of demarcation cannot be 
drawn between systems in every case, for occasionally 
a given system may combine methods related to 
two differing systems. The descriptions given in the 
following paragraphs are for convenience in present- 
ing the systems. Approved definitions may be found 
in NSA Basic Cryptologic Glossary. 

a. Transposition System. A cryptographic system 
in which the elements of the plaintext (individual 


letters, groups of letters, syllables, words, phrases, 
sentences, or code groups or their components), 
undergo some change in their relative position with- 
out a change in their identity. The three major 
classes of transposition systems are: 

(1) Single transposition. Those systems wherein 
the plaintext undergoes only one transposition. 

(2) Polyphase transposition. Transposition sys- 
tems wherein the plaintext undergoes two or more 
transpositions. Of this type transposition, double 
transposition is most common. 

(3) Grille transposition. A transposition system 
involving the use of two devices; a matrix of given 
size, and a grille, a thin material in which perforations 
have been made. Normally the plaintext message is 


—-GONFIDENTFIAL__ 1-5 


inscribed in the cells of the matrix, one word or letter 
per cell, in normal left-to-right, top-to-bottom order. 
The grille is then placed over the matrix, the perfora- 
tions exposing portions of the plaintext. These are 
extracted and recorded and the grille is revolved. 
Again more plaintext is exposed. This process is 
continued until all the plaintext has been extracted 
from the matrix, the process transposing the relative 
order of the words or letters of the plaintext. 

b. Substitution System. A cryptographic system 
which involves the replacement of the plaintext value 
by one or more ciphertext values with no change 
between their relative order of occurrence. Both or 
either of the plaintext and ciphertext values may be 
of equal or different length and form the basis of the 
further subclassification of the system. 

(1) Monoalphabetic substitution. A system of 
substitution involving a single fixed cipher sequence 
from which a cipher equivalent of one or more ele- 
ments is drawn in all cases to pepnsens one plaintext 
unit of equal length. 

(a) Monographie sibeinieon. Monoalphabetic 
substitution system in which the plaintext units 
replaced are always single units, letters, or numbers; 
but in which the length of the cipher unit may vary. 

1. Uniliteral substitution. Monographic sub- 
stitution in which single letters or numbers of the 
plaintext are replaced by single cipher equivalents. 

2. Mudltiliteral substitution. Monographic 
substitution in which single letters of the plaintext 
are replaced by cipher units of two or more characters. 

(6) Polygraphic substitution. Substitution sys- 
tems in which the plaintext units treated are group- 
ings of more than one element of regular length, 
replaced by cipher elements of similar length. 


(2) Polyalphabetic substitution. A system of sub- 
stitution in which successive plaintext elements of a 
message are replaced by cipher elements drawn from 
a succession of different cipher alphabets. 

(a) Periodic polyalphabetic substitution. A 
method of polyalphabetic substitution in which a 
series of cipher alphabets are used cyclically, also 
called repeating key. 

(b) Aperiodic polyalphabetic substitution. A 
method of polyalphabetic substitution in which the 
method of substitution results in the suppression of 
cyclical phenomena in the cryptographic text. 

c. Application of Systems. Transposition systems, 
particularly the polyphase systems, excepting double 
transposition, although offering a greater degree of 
security than some substitution systems, find little 
application in military communications. Complexity 
of operation, time required for their use, the limita- 
tions on message length, and the practical difficulties 
encountered in producing and distributing the ma- 
terial required for their use, all serve to limit their 
effective use. 


1-13. K Code System 


a. Code systems differ from cipher systems in that 
the substitution of values does not involve a one- 
to-one ratio. A group of arbitrary length, usually 
three to five letters, figures, or combinations, is 
substituted for either letters, syllables, phrases, or 
sentences. 

b. The mechanics of a code syeiam are such that 
usually some method of listing the code groups and 
their associated plaintext values is required. A 
detailed explanation of code systems and their 
classification is given in Part Six. 


1-6 CONFIDENTIAL— 


CHAPTER 2 (C) 
SECURITY OF CRYPTOGRAPHIC SYSTEMS 


Section I. (C) GENERAL 


2~1. (Practical Requirement of a Military 
Cryptographic System 

Cryptographic systems must meet certain funda- 
mental requirements of a practical nature for use in 
military communications. In order of importance, 
these requirements are: reliability, security, rapidity, 
flexibility, and applicability. 

a. Reliability means that the cryptographic sys- 
tem, whether a code book, a cipher machine or device, 
or cipher table, will be on hand and in good working 
order, available for instant use. When used, it can be 
operative as long as needed. It also means that the 
cryptogram produced can be decrypted quickly, 
accurately, and without uncertainty as to meaning. 
Simplicity is implied in reliability; usually, the more 
simple the system the more reliable it is. 

b. The needs for both security and rapidity in a 
military cryptographic system are often conflicting 
requirements. Security is the total protection afforded 
by a sound cryptographic system; rapidity is the 
speed of operation of the system. Maximum security 
at all times is the goal, but cannot always be met. 
Often a compromise between these differing require- 
ments must be effected. In messages exchanged 
among higher headquarters, some speed may be 
sacrificed to attain greater security. Among lower 
headquarters and between units conducting active 
operations, security must often give way to the 
greater need for speed in communications. 

c. Concerning flexibility, a cryptographic system 
should have as wide an application as possible. 
A system specifically adapted to a particular usage 
cannot serve as an all-purpose system. A code book 
designed for field operations can hardly serve the 
needs of a high headquarters, nor can a system 
designed for it serve the needs of smal! combat units. 

d. The last factor concerns general application of 
the system. 

(1) Cryptograms produced by the system must 
be in a form suitable for transmission by means 
available to the using unit. 

(2) The system, especially that used at lower 


echelons, should be relatively simple in its operation 
and should be operable under different field conditions. 

(3) The system must be such that errors in the 
cryptographic process can be either corrected easily 
and quickly by the operator or be of no consequence 
in the decipherment process. 

(4) The system, if a device or a machine, must 
be light in weight, rugged in construction, and simple 
to operate, requiring the use of only one operator. 

e. In order to satisfy the conflicting requirements 
posed by all the foregoing factors, several crypto- 
graphic systems are available to each unit or head- 
quarters. This procedure permits the fulfillment by 
each unit of its own immediate needs for a system. 
oriented to its mission, plus it provides a .secure 
means of communications between adjacent units 
and higher and lower headquarters. 


2-92. (Ff Security Requirements of a Military 
Cryptographic System 

a. The ideal cryptographic system for military 
purposes is a single all-purpose system which is 
practical for use by the highest headquarters and 
by the smallest troop unit in the combat area, and 
which also presents such a great degree of crypto- 
graphic security that, no matter how much traffic 
became available all in the same key, the crypto- 
grams composing this traffic would resist solution 
indefinitely. Such an ideal system, however, is 
beyond the realms of possibility so far as present 
methods of cryptographic communications are con- 
cerned. For this reason, and those discussed in the 
preceding paragraph, a multiplicity of systems 
must be employed, each designed for a specific 
purpose, at a given lovel of security. 

b. The best that can be expected for each system 
is that the degree of security be great enough to 
delay solutions for such a length of time that, when 
the solutions are finally reached, the information 
obtained by the enemy has lost all its ‘‘short term,” 
immediate, or operational value, and much of its 
“long term,’’ research or historical value. 


CONFIDENTIAL— 24 


CONFIDENTIAL — 


2-3. (Go Exploitation of Cryptographic Systems 


In theory, all cryptographic systems are vulnerable 
to analysis and exploitation, given sufficient time, 
organization, skill, and volume of traffic. Analysis 
can be accomplished even if the general system and 
the specific keys are unknown at the start. In actual 
practice, however, the security of a. cryptographic 
system, and therefore its degree of vulnerability to 
analysis, are correlated directly to: 

a. The cryptographic soundness of the system. 
The degree of security of any system depends on 
this factor, and in turn determines the resistance to 
analysis which the system offers. A sound system, 
in the sense that the cryptographic process provides 
a maximum of variant values with little or no char- 
acteristic patterns subject to analytic attack, will 
resist analysis longer than a weak cryptographic 
system, all other factors being equal. 

b. The adequacy and soundness of the operating 
instructions pertaining to a system and the extent 
to which the users follow these instructions. Security 
of a good cryptographic system can be almost com- 
pletely destroyed by the users who, through care- 
lessness or ignorance, fail to follow prescribed 
methods of operation or who change operating 
procedures in the mistaken belief that they are 
improving the system. 

c. The volume of cryptographic text available 


for study. As a rule, the greater the volume of text, 
the more easily and speedily a system can be solved. 
A single cryptogram in a given system may present 
an almost impossible task to the cryptanalyst, but 
if many cryptograms are available in the same 
system in the same or in closely related specific 
keys, the solution may be reached in a very short 
time. 

d. The number, skill, efficiency, and organization 
of personnel and units assigned to the analysis of 
communications. This factor plays a direct part in 
the analysis and exploitation of a system. The 
simplest system may resist cryptanalytic attack if 
the analysts are unskilled. Even if a system is solved, 
the information may not be fully exploited if it 
lacks proper organization for this purpose. 

e. The amount and character of collateral in- 
formation and intelligence available. Cryptograms 
between correspondents about whom no information 
is available may pose a very difficult problem. 
If, however, a certain amount of information is 
known, a solution may be readily obtained. The 
more information at hand concerning a_ given 
cryptogram (including particulars of the basic 
system, as well as knowledge of its possible contents, 
i.e. proper names, stereotyped beginnings and 
endings, and events or subjects referenced in the 
message), the easier the solution. 


Section Il. (C) THE CRYPTANALYTIC ATTACK 


2-4, Communications Intelligence Operations 
Communications Intelligence (COMINT) operations 
study enemy communications for the purpose of 
obtaining information and intelligence. COMINT 
includes the collecting, processing, evaluating, and 
reporting of intelligence derived from raw data. 
COMINT attempts to answer three questions 
concerning enemy communications: Who, Where, 
and What; who are the originators and addressees, 
where are they located, and what do the messages 
say. 

a. The two steps in the series of activities whose 
end objective is to answer these questions are the 
collection of raw data, and the study and analysis 
of this data. 

(1) Collection. 

(a) Intercept operations. Intercept operations 
include all activities and functions directly related 
to the intercepting and recording of enemy radio 
communications. Major functions which are a part 
of intercept operations are the mission assignment 
and control, the allocation of equipment and 
facilities; and the assignment and direction of 
personnel. As an adjunct to intercept operations, 


providing both support to the intercept effort and 
a source of information to their own right, two 
special collection techniques are available. 

<i (b) Radio fingerprinting (RFP). RFP is the 
technique of identifying radio transmitters by 
recording on film, and later by analyzing the power 
and frequeney variations of an on-off keyed Con- 
tinuous Wave (CW) emission. 

(c) Radio direction finding (RDF). RDF is 
the technique of determining the azimuth (bearing) 
of a transmitter from the point of interception. By 
establishing the bearing on a transmitter from 
several different points, it is possible to fix the geo- 
graphic location of the emitter. 

(2) Study and analysis. The second step in 
COMINT operations is the study and analysis of 
all data provided by the preceding intercept activi- 
ties. The preliminary processing of this data nor- 
mally occurs in a traffic analysis section. Traffic 
analysis is the study of the externals of signal 
communications by all means short of the crypt- 
analysis of the message text. Traffic analysis re- 
constructs radio communications networks by noting 
volume, direction, and routing of messages; 


2 CONFIDENTIAL 


CONFIDENTIAL — 


correlating transmission frequencies and schedules 
used among a network’s various stations and nets; 
determining the location of radio stations by evalu- 
ating the results of radio direction finding; identifying 
radio station association by evaluating the results of 
radio fingerprinting; recovering the system or systems 
of generating, assigning, and changing radio callsigns; 
and studying all items that constitute messages 
originated by operators and exchanged among them- 
selves on a radio net. 

° (a) Information gleaned by the traffic analyst 
serves two general purposes. First, it provides a 
basis for further interception of the enemy’s com- 
munications. Second, it produces information that 
is of intelligence value in itself, and also of great 
value to the cryptanalyst in his attack upon the 
message text. Traffic analysis is able not only to 
ascertain the geographic locations and dispositions 
of troop units and headquarters, but also sometimes 
can predict, with varying degrees of reliability, the 
areas and extent of immediately pending or future 
activities of the enemy. This can be done without 
reading the text of the intercepted message. Specifi- 
cally, enemy plans and operations may be revealed by: 

1. Movement, appearance, and disappear- 
ance of radio stations. 

2. Changes in volume and routing of 
messages. 

3. Characteristics of messages and any 
changes thereto. 

4. Redeployment and changes in com- 
munications networks. : 

§. Allusion to operations in radio operator 
chatter. 

(6) On the basis of the foregoing studies it is 
possible to accurately answer the first two questions, 
Who and Where, and, in some cases find a partial 
answer to the third question, What. However, the 
final answer to the third question can only be found 
with certainty in the message text itself. This is a 
task of the cryptanalyst. 

b. Cryptanalysis is the process involved in con- 
verting encrypted messages into plaintext without 
initial knowledge of the system or key employed 
in the encryption process. The solution of practically 
every cryptogram under these conditions involves 
four fundamental operations: 

(1) The determination of the language used in 
the plaintext version. 

(2) The determination of the general system 
of cryptography used. 

(3) The reconstruction of the specific key in 
the case of a cipher system; or the reconstruction, 
partial or complete, of the code book, in the case of 
a code system, or both in the case of enciphered codes. 


468-095 O - 72 -:2 


(4) The reconstruction or establishment of the 
plaintext. 


2-5. (C) Determination of Language 

a. The determination of the language employed 
seldom comes into question where studies are 
made of the cryptograms of an organized enemy. 
During conventional war when the enemy is known, 
the language employed in messages will most likely 
be in the enemy’s native tongue. Where this is not 
the case, ie. when cryptograms of unknown origin 
must be studied, the cryptanalyst looks for indica- 
tions of the language in the cryptogram itself. 
Addresses, signatures, and other data in plaintext in 
the preamble, in the body, or in the postamble of 
the cryptogram may reveal the language used, as 
well as those external elements associated with the 
transmission of the message. 

b. In special cases, the nature and composition 
of the cryptographic text may reveal the language 
used. For example, if the letters K and W aro absent, 
the language may be Spanish or Portuguese, as 
these letters are used only to spell foreign words. 
The presence of special characters in the text may 
also indicate the language where the alphabet 
exceeds the Morse code equivalents. For example, 
KATA KANA, a Japenese syllabic writing having 
72 syllabic sounds, requires 48 Morse code characters 
for radio transmission, creating a form of Morse 
code called Kana Morse code. 

c. Knowledge of the language used in a given 
cryptogram is important in two respects. First, 
the frequency of occurrence and distinctive pecular- 
ities of combining individual letters, vowels, con- 
sonants, digraphs, and trigraphs, varies with different 
alphabetic based languages, but individually are 
rather constant, a feature that becomes the basis 
for analysis. Second, final solution and translation 
of the message depends upon the ability to make 
valid assumptions of word usage. 

d. In some cases it is possible to perform certain 
steps before the language of the crvptogram is known. 
Frequency studies may be made and certain analytic 
processes begun without this knowledge. Final 
solution, however, usually depends on the analyst 
knowing valid combinations of letters, svllables, and 


‘some common military terminology in that language, 


or having available a translator who can aid him in 
making necessary assumptions based upon his 
special knowledge of the characteristics of the 
language in question. 


2-6. (Q Isolation of the General System 

a. Determining the general system in which a 
given cryptogram has been enciphered is the most 
difficult step in its solution, except for some of the 


“CONFIDENTIAL — 2-3 


a 


“CONFIDENTIAL — 


simpler basic systems. The solution of every crypto- 
gram involving a form of substitution depends upon 
its reduction to monoalphabetic terms. This is also 
true of combined substitution-transposition ciphers 
and enciphered codes. In the case of transposition 
ciphers, recognition of the system, followed by 
determination of the method of transposition is 
required. 

b. To achieve these ends, however, a degree of 
prior knowledge is required; knowledge of how a 
given cryptographic system operates, its character- 
istics, and its limitations. The analyst must be able 
to identify the cryptogram under study as one of the 
basic systems. The knowledge of cryptographic 
systems comes from training and experience; identi- 
fication of a cryptographic system is a matter of 
analytic determination. 

c. Cryptanalysis offers few tests that may be 
applied to a cryptogram to determine positively 
to which class it belongs, particularly in the case of 
two systems yielding externally similar results. 
However, the analyst, if he can identify a system to a 
general class, can usually determine by trial and 
error the exact class to which it belongs. Sooner or 
later most systems can be identified, either because 
of blunders or carelessness on the part of the crypto- 
graphic clerks, or because the accumulation of a 


volume of traffic makes possible its identification — 


by cryptanalytic and statistical studies. In the case 
of isolated cryptograms, identification of a system is 
sometimes g- matter of a shrewd guess. 

2-7. ie of the Specific Key 

Most cryptographic systems use a specific key to 
guide, control, or modify the processing steps of 
the general system. Once the system is known, the 
next step in the solution of a cryptogram is to 
determine the specific key, if used, employed to 
produce the cryptogram. This determination may 
not be required in complete detail; it may be 
sufficient to know the number of alphabets involved 
in a substitution system, or the number of columns 
in a transposition system, or that a code system is 
one-part. In other cases, a complete recovery 
may be desirable for use as a clue to the operation 
of an unsolved related system. In many cases, the 
reconstruction of the specific key and the recovery 
of the plaintext may be simultaneous operations. 
The primary requirement for specific key recovery 
in most cases is to provide the basis for the rapid 
solution of cryptograms enciphered in the system 
using the same key or similar key. 


2-8. (C) Recovery of the Plaintext 
a. In the case of substitution ciphers, this process 
involves establishing equivalency between specific 


letters of the ciphertext and the plaintext, letter by 
letter, pair by pair, ete., depending upon the type 
of substitution cipher involved. In the case of trans- 
position ciphers, the process involves rearranging 
the elements of the ciphertext, according to the 
peculiarities of the system, until the plaintext has 
been recovered. In the case of codes, the process is 
one of determining the meaning of each code group. 
b. The above processes for any system are not 
sequential. The identification of plaintext values 
comes at very irregular intervals. At first, only one 
or two values are recovered and appear scattered 
‘throughout the ciphertext. These letters form the 
“skeletons” of words, upon which further work, 
continuing the reconstruction process and assuming 
words to be tested, recovers the complete text. The 
recovery of the plaintext is a long tedious process 
involving a great deal of work and analysis. 


2-9, af Steps of Cryptanalysis 


Any scheme of analysis is based upon successive 
elimination of alternatives, therefore the crypt- 
analyst can only progress as far as the extent of his 
own knowledge of the possible alternatives. Addi- 
tionally, the general procedures and techniques of 
analysis will differ from one system to another due 
to the characteristics of each system that lends itself 
to analytic attack. For these reasons it is difficult to 
specify which exact steps will be followed in all 
cases. The most important steps of practical, opera- 
tional cryptanalysis are listed below in outline form. 
These steps appear in the order in which they are 
usually followed, but in particular cases, some of 
these steps may be interchanged or omitted entirely. 

a. The study of the characteristics of the message 
text. 

b. The study of any available collateral infor- 
mation. 

c. The search for and study of indicators in the 
message text. 

d. The determination of the type cryptographic 
system used. 

e. The separation and classification of messages 
into common groups determined by general system 
or related specific keys. 

f. The search for repetition of groups, symbols 
within and between messages of the same system. 

g. The study of the beginnings and endings of 
messages for stereotypes. 

h. The preparation of statistical counts of mes- 
sage elements. 

i. The reduction of the encrypted text to the sum- 
plest terms. 

j. The test for probable words, stereotypes, and 
isologs. 

k. The recoverv of the plaintext. 


2-4 GONFIDENTFIAL 


CONFIDENTIAL- 


Section Ill. SS ANALYTIC AIDS 


2-10. (J Introduction 

a. Several different statistical tests, tables, and 
many different data listings, are available to the 
analyst as analytic aids. The tests are generally 
used for the initial identification of a system, 
enabling the analyst to identify a system to its par- 
ticular class, substitution or transposition, and in 
some cases allowing the determination of type, 
monoalphabetic or nonmonoalphabetic substitution. 
However, the analyst should understand at the 
outset that the results given by these tests are not 
always absolutely reliable. In certain cases, the in- 
herent characteristics of the ciphertext may be such 
that the test results are misleading if not totally 
false. The significance is that the analyst should 
not accept at face value the results of one test. 
Rather, identification should be based on several 
factors. 


explained. In subsequent chapters where the tests 
have specific application, they will again be ex- 
plained in terms of each case. Also in the same areas, 
other tests which serve a purpose only in a given 
set of circumstances will be explained and the 
techniques of their application discussed. 

e. The lists of data used by the analyst in the 
analysis of u cryptogram, and which have general 
application in this context only are contained in 
the appendixes. As they become applicable they 
will be discussed and their use illustrated. 


2-11. Uniliteral Frequency Distribution 

a. The individual letters of any alphabetic-based 
language, when used in intelligible text, occur with 
greatly varying frequency. If, for example, a tabu- 
lation is made of the occurrence of the individual 
letters in the preceding sentence, shown in figure 


b. In the following paragraphs, the more common 2-1, the variation in frequency is strikingly 
and immediately useful tests are introduced and demonstrated. 
= 
= 4 Zz = = = 
Z=22itZ= Zz 2 @ #@2=-= ~~ _Z2 He =z _ez 
ABcODBEFGHtIJ«K LMNOPQRs TUVWéKY =Z 
1 1 
Bs ee Be BG Qe Oy ABE). BE a SB RS SQ Ree Se ae a 


Figure 2-1 (U). Frequency tabulation 1 (U). 


If the letters of the second sentence in the preceding 
paragraph are tabulated as shown in figure 2-2, the 


following occurrence 


of individual letters will be 


found. 


= __2 Z Z#=2 = # 
P_2222-37 #272. 332=- 
ee ee eee 
ee 2 ee ee ee ee ee 


Figure 2-2 (U). Frequency tabulation 2 (UV). 


Although a difference in the frequency of occurrence 
of single letters, as reflected in peaks and troughs of 
each distribution, is observable in both distributions 


ABCD 


EFGH IJKL™M™M 
1 1 
9 3 4 4 4354 0008 9 
2 l 
9166 0524 4015 3 


very little difference is observed when the frequency 


of occurrences of 


is 


NOPQRsS 


8 
1 
2 


given letters in both distributions 
compared. 


PV Wxey g 


211 5 8 9522 1 4 0 
1 
7 2 1 8 6 3420120 


2-5 


GONFIDENTIAC 


In both of the distributions, note that certain letters 
occur much more frequently than others. The letters 
A, E, I, N, O, R, and T occur with the greatest 
frequency. The letters C, G, H, L, P, and S occur 
less often. The letters F, J, K, Q, V, X, and Z occur 
infrequently, or not at all. A degree of simuanty 
between the two distributions is greater if the two 
texts used in the tabulation are longer. In fact, when 
two different texts of 1,000 or more letters are com- 
pared, the frequencies of occurrence of individual 
letters show only the slightest variation. Beyond that, 
the practical gain in accuracy does not warrant 
further increase in the amount of text. 

b. The standard uniliteral frequency distribution 
for English telegraphic plaintext, derived from a 
tabulation of 50,000 letters, and reduced to a base 
of 1,000 which may be used as a tool in the analysis 
of cryptograms in the English language, is given in 
figure 2~3. 

c. The preceding figures reveal several facts of 
great importance to the cryptanalyst and cryptog- 
rapher. 

(1) The standard uniliteral frequency distribu- 
tion is quite irregular, having marked peaks and 
troughs, points of high and low trequency. 

(2) The relative position within the standard 
uniliteral frequency distribution of the peaks and 
troughs is relatively fixed, determined by the sequence 


of the letters of the alphabet and their frequency 
of usage. 

(3) The relative height and depth of the peaks 
and troughs are also relatively fixed, varying only 
slightly, and this is determined largely by the size 
of the sample tabulated. 

(4) The most prominent crests are marked by 
the vowels A, E, I, and O, and the consonants N, 
R, S, and T. The deepest troughs are the consonants 
J, K, Q, X, and Z. 

(5) The four vowels, A, E, I, and O, and the 
four consonants, N, R, S, and T, representing a 
combined frequency of 666 of 1,000 letters, approxi- 
mately one-third of the alphabet, are used in writing 
two-thirds of normal plaintext messages. 

d. Should an alphabet be so changed, or used in 
such # manner as to either change the sequence of 
the alphabetic values, or the frequency of usage of 
individual letters, the peaks and troughs would be 
changed accordingly, both in relative order and in 
total value. However, these changes, as will be 
shown in following paragraphs, can be directly re- 
lated to the use of plaintext, as the true values must 
remain constant. 

e. The data given above is based on English 
telegraphic text derived from government adminis- 
trative messages. A similar distribution drawn from 
another source can be expected to show some 


In Alphabetic Order 


G H I J K L 


de ot OE 3 
6 4& & 2 3 6 


M 


2 
? 


N O P Q 
1 
2 


T 
2 3 


In Relative Order of Frequency 


S) iC F P U 


6 


B uO es 2 a 
1 he 2 BT 6" Bs DO p 


MY 


3 2 


frequency percent percent in round numbers 


Vowels: 

AETOUY 
Consonants: 

High Freq DN RST 
Med Freq BC FGHLM 
Low Freq J K Q XZ 


Figure 2-3 (U). Standard uniliteral frequency distribution (U). 


2-6 


CONFIDENTIAL- 


variation, the degree of variance being dictated by 
the source. For example, a distribution tabulated 
from messages pertaining to international shipping 
activities is markedly different, caused by the use 
of words peculiar to the business. Also, a distribu- 
tion of a message in a foreign language is different, 
due to the nature of that language’s alphabet, 
spelling, and word usage. However, for any given 
set. of circumstances, which remain constant, a 
standard uniliteral frequency distribution can be 
derived. Variations may occur in each, because of 
volume available for tabulation or subject matter, 
but given sufficient volume, a normal distribution 
can be derived which forms a basis for the initial 
study 


of a cyyptogram. 
2-12. Use of the Standard Uniliteral Fre- 


quency Distribution 
Three facts can be determined by a comparison of 
the standard uniliteral frequency distribution to a 
uniliteral frequency distribution drawn from a cipher 
message composed of letters. First, whether the 


Cryptogram No. 1 HAMEA 
NPRIO 
NEBAC 
SSSYA 
TIODR 


Cryptogram ilo. 2 


VAAEI 
INLYRT 
REEELA 
2SDII 
WNILN 
AWERE 


Cryptogram No. 3 


ty 
o~ oT 
> Hill 
r+ co ts THOM, TNHUTHHL | 
no hl 
re il 
ae A HUM 
Il 
me 


Q 


we > HUT, TH, 
HAL TII 


4 


[o) 
Oo 


219 


EROSY 


IRXCC 
00S00 
HRARN 


LZZMO 
OORTS 
RFAXI 
IOERE 
ROFUF 
LERRA 


b+ & THMMUIll 


cipher belongs to the substitution or transposition 
class. Second, if substitution, whether the cipher is 
monoalphabetic or polyalphabetic. Third, if the 
cipher is monoalphabetic, whether the cipher com- 
ponent is a standard (direct or reversed) or a mixed 
sequence. 

a. The difference between a transposition system 
and a substitution system is that in transposition, 
the plaintext has been rearranged, conventional 
values remaining the same in all cases. In substitu- 
tion, the identities or values of the letters of the 
plaintext have been changed giving rise to the 
ciphertext of the message. Consequently in a trans~ 
position cipher, a count of the letters should corre- 
spond closely to the standard uniliteral frequency 
distribution, both in frequency of occurrence of the 
individual letters and in their spatial relationship, 
i.e. the location of the peaks and troughs. 


For example, a frequency count of the following 
cryptograms produced by transposition ciphers ap- 
pears in figure 2-4. 


ATUTS DEEET QRDRU USYLP 
PMPIS 
ANFSE 
LIRWN 


SSLEL 
OEOYI 
ATNNT 


VCTEL 
NSIAT 
OTIEA 


HNEVE 
PLORO 
OUTER 
QO0ST 
HTUSF 
DE 


APLEF 
ARRON 
OTSEK 
ECLSO 
TIFTS 


LOXIL 
ECT2L 
JUPPE 
SYEIO 
SVUOC 


© THU MOHU OAL 


ro HHL I 


wo 1 2 ALTAIR I 
© THU 


no-no to THA THRILL 
He > ss THOTT 


= = a 
M Q Vw x ¥ Z 
3 3 8 7 2 8 3 3 4 6 5 


Figure 2-4 p. Uniliteral frequency distribution, transposition cipher (U). 


CONFIDENTIAL — 


2-7 


Converted to an equal base and compared to the 
standard uniliteral frequency distribution, it appears 
in figure 2-5. On this basis one assumed with a certain 
degree of security that the cipher in question is a trans- 
position system rather than a substitution system. 
b. In monoalphabetic substitution ciphers, the 
identities of the letters are changed on a one-to-one 
basis, i.e. Ap may become Xc and Xp may become 
Ac; Ap by definition cannot be represented by more 
than one cipher value. Since the identities of the 
letters are changed, the frequency of appearance of 
the letters are changed. The frequency of appear- 
ance of vowels, and high-, medium-, and low- 
frequency consonants are quite different from what 
they were in the plaintext. This may be seen in 
figure 2-6 depicting a message enciphered in a 
monoalphabetic substitution system, and its ac- 
companying uniliteral frequency distribution. 


150-4 


125 


100 


a 
CI 


s 
L 


| tt 
STUVWXY2 


4 Z| 2a 
ABCDEFGHIJKLMNOPQR 


Figure 2-5 (U). Comparison, standard uniliteral frequency 
distribution and transposition ciphertert (U). 


YHYGS UWNCP CNSCH KOUHA HAUCJ LIPCH WYWIH MCHOC HAQCN BYHYG 


GCHCN CUNCH AWIHN UWNMV SMHCJ YLZCL YGLIN ULUNN UWEMU HXCHN 


YLXCW NCIHI ZFIWM VSGCH YMUHX VIIVS NLUJM WUJNO LYXJQ CHUIM 


NUNYX NBUNN QIIHY LYACG YHNWO LLYHN FSYHA UAYXC HLYMO JJFSU 


WNCPC NCYMU HXJFU HMZIL IZZYH MCPYU WNCIH CHUOA OMNNB CMULY 


com oo HOM] THOM 


z = 
= z= £Z 
z= ~= 2222-2 
ABCDEPFPGH Id KL 

i 1 
Cae o 14 5 


» = TH 1 
no = TUM EN THIN | 


05-8 2d A GT SB O28: -O.. 3. 5 


= = 
Zz = 2 
2=S2= 4 222222 
OP QRSs Tf UV WX Y @ 
2 aa 2 
2 2 


“A 
a 


Figure 2-6 6. Uniliteral frequency distribution, monoalphabetic substitution cipher (U). 


Enlarged to a base of 1,000 by multiplication and 
compared to a standard uniliteral frequency dis- 
tribution, it appears as in figure 2-7. A comparison of 
the two shows that it does not correspond to the 
expected norm. Expected high-frequency letters 
appear as low-frequency letters, low-frequency 
letters become medium-frequency, and medium- 
frequency letters are both high and low. Close 


inspection will show that the ciphertext still ex- 
hibits marked peaks and troughs, and a definite 
spatial relationship exists between them; both are 
characteristics of monoalphabetic substitution where 
only the value of the letters are changed, and conse- 
quently the frequencies of occurrence of individual 
letters are not suppressed. If the system is non- 
monoalphabetic, where the possibility exists that 


2-6 CONFIDENTIAL 


= 


HH 
Cy 
HH 
= 
EEE 
tH 
| 


= 
i 
a 
: 
a 


= am 
rf Fy 
LH i 
as 
; H 
TI 
= 
r+ 
PPLE 


TS 


i] YT 
2 i a | ee 
BEE go 
A FOHTIK LMNOPQRSTUV YZ 


Figure 2-7 (U). Comparison, standard uniliteral frequency 
distribution and monoalphabetic substitution cipher (U). 


one plaintext letter is represented by a number of 
different cipher letters, the peaks and troughs are 
suppressed and leveled off. 

ce. Once it has been determined that a given 
cipher alphabet is monoalphabetic, represented by 
the text of a cryptogram, the type alphabet (direct 
or reversed standard, or mixed) can be identified by 
comparing the spatial relationships of its peaks and 
* troughs with those of the standard uniliteral fre- 
quency distribution. For example, if the frequency 
distribution for the cipher shown above is moved 
seven places to the right, where Ue corresponds to 
Ap, the peaks and troughs of the two distributions 
can be brought into alinement. This relationship is 
shown more clearly in figure 2~8 where each alphabet 
and its associated frequency distribution is in- 
scribed on two wheels which can be moved against 
one another. 


d. Identification of the use of direct standard 
reversed cipher alphabets and mixed sequence cipher 
alphabets employs the same techniques of comparing 
the peaks and troughs of the cipher alphabets in 
question against those of the standard uniliteral 
frequency distribution. For example, compare the 
cipher alphabets shown below to their associated 
standard uniliteral frequency distributions. In figure 
2-9@, note that the spatial relationships are the 
same, except that the one representing the cipher- 
text is directly reversed, indicating that the alpha- 
betic values it represents are also reversed. In 
figure 2-9@, no matter how the two alphabets are 
placed against one another, alinement is impossible, 
without a rearrangement of the letters of the cipher- 
text. Once this is done, however, peaks and troughs 
can be alined. 


NORMAL 
UNILITERAL 
FREQUENCY 
DISTRIBUTION 


CIPHER TEXT 


. Potnt of coincidence, normal uniliteral fre- 
quency distribution and ciphertext (l). 


Figure 2-8 


2-13. Variations in a Uniliteral Frequency 
Distribution 

a. In the preceding paragraphs, identification is 
predicated on the fact that usually the frequency 
distribution of a transposition cipher is very close 
to that of normal plaintext, while usually in a sub- 
stitution cipher they are far different, making identi- 
fication of either a simple matter. This is not always 
the case, however, for as messages decrease in length, 
there may be greater and greater departure from 
the normal proportion of vowels, and high-, low-, 
and medium-consonants used. This situation will 
limit the use of the standard uniliteral frequency 
distribution for identification purposes. 

b. Statistical studies show the theoretical devia- 
tion from the norm. The following charts, one for 
each vowel (fig. 2-10), and for high-frequency 
(fig. 2-11), medium-frequency (fig. 2~12), and low- 
frequency (fig. 2-13) consonants, illustrate expected 
variations in frequency of occurrence by message 
length. The time of occurrence is shown on the 
vertical line, message length on the horizontal line, 
and maximum and minimum occurrences indicated 


“CONFIDENTIAL ___ 2-9 


AH 


See KEe a ARR a 
SERRE cL 2Ee AREER BS Ss AEE eee eee 


ay J 
f| 


at 


ee 


IAN TT ee TAT YT 
BA Se Re 


Figure 2~9@ (U). Comparison, standard uniliteral distribution and mized cipher alphabet (U). 


by the upper and lower lines of the graph respec- 
tively. For example, in a plaintext message of 100 
letters, the combined number of vowels appearing 


in it eae within the range of 32 to 48 letters. 
2-14, The Lambda (A) Test 


a. The Lambda or blank expectation test is 
another means of determining whether a cipher 
message is monoalphabetic or nonmonoalphabetic. 
It is normally used on messages of 200 letters or 
less, assuming that messages of greater length can 
be identified easier by other methods. The test is 


based on the number of nonoccurrences of letters in 
a message. Statistical studies show that a predictable 
number of blanks will occur in plaintext messages, 
the exact number varying with the length of the 
message. Statistical studies also show that the 
theoretical numbers of blanks that will occur in a 
completely random assortment of letters differ from 
the expected number of blanks occurring in plaintext 
messages of equal length. From this information 
the blank expectation chart (fig. 2-14) has been 
devised which compares the expected number of 
blanks in plaintext and in random text, which in 


2-10 GONFIDENTIAL 


CONFIDENTIAL 


Number of vowels (AEIOUY) 


6030 100 120 0 160 180 200 


Number of letters in message 
Figure 2-10 Pe occurrence of vowels, English plain- 


text (U). 


Number of high frequency consonants (DNRST) - 
HHH | 
N+ [| 


Number of letters in message 


Figure 2-11 . Expected occurrence of high-frequency con- 


sonants, English plaintext (U). 


effect is the same as the number of blanks expected 
in a cipher message based on a nonmonoalphabetic 
cipher. 

b. Curve P in the chart indicates the number of 
expected blanks in a plaintext message and curve 
R the number of expected blanks in a random 
(nonmonoalphabetic cipher message) assortment of 
letters. To use the chart, find the number of blanks 
in the message under study. Locate this number on 
the vertical line indicating the number of expected 
blanks, locate the total number of letters in the 
message on the horizontal line, and then locate the 
point of intersection of these two points on the 
chart. Should the point of intersection fall closer to 
the P curve than to the R curve it is probably 


40 60 80 100 120 140 160 180 200 


Number of letters in message 
Figure 2-12 . Expected occurrence of medium-frequency 


consonants, English plaintext (U). 


Number of medium frequency consonants (BCFGHLMPYW) 


Number of low frequency consonants ()KQX7Z) 


60 30 100 120 140 160 180 200 
Number of. letters in message 


Figure 2-13 A Expected occurrence of low-frequency 
consonants, English plaintert (U). 


0 2 40 


either a simple substitution or a transposition 
cipher. If, however, the point of intersection falls 
closer to the R curve, the message is probably 
enciphered in a nonmonoalphabetic system. 

c. These charts may be used to identify the class 
of a cipher in addition to supplementing the stand- 
ard uniliteral frequency distribution. If the count 
of a class of letters, vowels or consonants, falls 
within the expected range shown by the upper and 
lower lines, it is assumed to be a transposition 
cipher; if outside, it is assumed to be a substitution 
cipher. Basis of reasoning for these identifications 
is the same as used previously, i.e. transposition 


‘GONFIDENTIAL— 2-11 


CONFIDENFAL- 


6 Td a 


Number of blanks 


—_ tL | 
a 2 40 60 80 100 120 HO 160 180 
Number of letters in message 


Figure 2-14. (U). The Lambda (X) test, expected number of 
blanks occurring in English plaintext (U). 


does not change the values of the letters while 
substitution does. The degree of accuracy of the 
identification is correlated to the distance that the 
point of intersection of the number of letters and 
message-length falls from or within the delimiting 
maximum-minimum lines. 
2-15. hi Phi (¢) Test 

a. In the preceding examples, ‘dentineation is 
based largely upon visual observation of character- 


istics present because sufficient depth, that is quan- 
tity of messages in a given cipher, is available. 


However, depth is not always available. Often an 
analyst must work with an extremely small volume 
of traffic, in which case a frequency distribution is 
likely to be inaccurate, due to the insufficiency of 
traffic as well as the normally expected variations 
of occurrence. For such cases, a mathematical test 
has been developed which allows identification of 
monoalphabetic or nonmonoalphabetic quality. 

6. This test is based upon the known frequency 
of occurrence of the specific letters of an alphabet, 
and the premise that these characteristic frequencies 
will be repeated in certain ciphers, even though the 
identity of the letters involved might be changed. 
For example, in English the letter E is normally one 
of the most frequently used letters. If in a cipher 
the letter X was substituted for the letter E, X 
then would appear in the ciphertext as often as E 
did in the plaintext. Also given an alphabet, the 
frequency of random occurrence of each of its letters 
can be calculated by statistical means. This fre- 
quency, random occurrence, represents the number 
of times a letter is liable to appear through pure 
chance alone where the text is solely a random mixture 
of all letters of the alphabet. Thus, two standards are 
available, the plaintext frequency of occurrence, 
and the random frequency of occurrence, for all 
alphabets. 

c. The @ test then is a comparison between the 
observed occurrences of the letters, of a cipher 
represented by ¢o, with the expected value of random 
occurrence, represented by ¢r, and the expected 
plaintext occurrence, represented by gp. The use of 
the @ test can be seen in figures 2-15 and 2-16. 


OWQWZ AEDTD QHHOB AWFTZ WODEO 


TUWRQ BDQRO XHQDA GTBDH PZRDK 


@) 
Figure 2-15 (C). The Phi (@) test, tabulation of frequencies (F) of letters (U). 


ea 
i 


Ss 
0 


= 
2 


wo Fo |] 


CV x Ye 
1 0 tO 3 


HO 
ari 


= do 


Figure 2-16 gh The Phi () test, calculation of ¢0 (U). 


ABC Ig K LM 

3 3 0 0 1 
== Z-__= —_ = _zZ 
33072114001000416 
ABCDEFGHIJSKIMNOP® 
4 a 1 3 
6602200200 0000200 
NY 2 50 
fo = 154 

2-12 


CONFIDENTIAL— 


CONFIDENTIAL’ 


d. Observed values of occurrence (go) for this 
distribution are calculated by applying the formula 
F(F-1) to the frequency of occurrence (F) of each 
letter and then totaling the sums of all. This is 
expressed mathematically as go=F(F-1). For 
example, F(F-1) ¢o of A=3(3-1)=3X2=6. This 
calculation is applied to each in turn, the individual 
sums then summed to derive the observed values of 
occurrence, ¢o. To determine the values of gr and 
op, the formulas ¢r=.0385N(N-1) and ¢p=.0667N 
(N-1) are used, where N is the sum of F of the dis- 
tribution. gr gives the value of expected random 
occurrence; @p gives the expected plaintext value 
for English military telegraphic text. The constants 
.0385 and .0667 are valid for English plaintext. The 
former (.0385) is the decimal equivalent of %., the 
reciprocal of the number of letters in the alphabet. 
The constant .0667 is the sum of the squares of the 
probabilities of occurrence of the individual letters 
in English plaintext. Where a different alphabet 
is involved, these constants are different, though 
the formulas remain the same. The calculations are: 


gr= .0385N (N-1) = .0385 X50 X49=94 
op= .0667 N (N-1) =.0667 X50 X49= 163 


e. Once the calculations are completed, the values 


for observed occurrence, random expected occurrence, 
and expected plaintext occurrence are compared. 


po= 154 
gr=94 
op = 163 


Since the value of go (154) is closer to the value of 
¢#p (163) than to the value of gr (94), the cipher is 


probably monoalphabetic. If it were closer to gr, 
a nonmonoalphabetic cipher is indicated. Non- 
monoalphabetic in this sense refers to the cipher 


being any one of the systems listedl previously in 
paragraph 1-11 which are not monoalphabetie. 
If, however, the valueof¢o were just halfway between 
gr and gp no assumption would be made on the 
basis of this test. 

jf. The basis for identification whether a message 
is monoalphabetic or nonmonoalphabetic is similar 
to the basis in preceding tests, i.e. the nonsuppres- 
sion of. frequencies of occurrence when monoalpha- 
betic ciphers are used, and their suppression by 
nonmonoalphabetic ciphers. The value of go ap- 
proaches the value ¢p in cases of nonsiippression, 
while the value of go approaches the value of 
gr where suppression occurs. The underlying reason 
for the latter is that nonmonoalphabetic systems 
tend to randomize the frequencies of observed 
occurrences in ciphertext. 


CONFIDENTIAL— 2-13 


PART TWO (C) 
TRANSPOSITION SYSTEMS 


CHAPTER 3 (C) 
GENERAL TRANSPOSITION SYSTEMS 


Section |. (C) GENERAL 


3-1. g Transposition Ciphers 


All tr@fsposition ciphers are alike in several respects. 
First, and most important, all the elements of the 
original message are present in their original identi- 
ties, only disarranged in sequence. Secorid, the 
individual bits into which the original plaintext 
message is divided by the transposition process are 
normally of equal length. They may be either 
single letters, pairs of letters, sets of letters, or in 
exceptional cases, whole words. Third, practically 
all transposition ciphers involve the use of matrices, 
a geometric design usually a square or a rectangle, 
with specific routes of inscription and transcription. 
The importance of these factors is the degree of 
constancy which they impart to cryptograms pro- 
duced by transposition systems which form the 
basis of their analysis. 


3-2. (U) Monoliteral, Polyliteral, and Word 
Transposition 

Transposition ciphers are classified by the structure 
of the elements manipulated in the transposition 
processes. Those that deal with individual letters of 
the plaintext are monoliteral transposition. Those 
that deal with a component of two or more letters 
are polyliteral transposition. Those wherein the 
elements are word length are termed word transpo- 
sition systems. It is possible to use any length ele- 
ment, as the length of the element does not affect 
the process of transposition. However, the mono- 
literal transposition systems are favored due to 
their practicality and security. 


3-3. (U) Single and Double Transposition 


Single and double transposition, also called mono- 
phase and polyphase, are transposition processes a 
plaintext message may undergo to become cipher- 
text. In single transposition, the elements transposed 
go through only one cycle: inscription into a matrix, 


and transcription to ciphertext. In double transpo- 
sition the elements undergo two cycles. The letters 
resulting from the first transposition cycle are again 
submitted to a transposition process. Triple and 
quadruple transpositions are possible but impractical 
for common use. Double transposition, while limited 
in its use due to the same practical considerations, 
does provide a great deal of security; often more 
security than that provided by certain much more 
complicated substitution methods. 


3-4. (YF Geometric Designs 

Most Aransposition systems use matrices for the 
inscription and transcription of the plaintext and 
ciphertext. Squares and rectangles are most com- 
monly used, although other geometric figures, e.g. 
triangles, trapezoids, and other polygons, are occa- 
sionally used. The square and rectangle are far 
superior to the other forms, being easier to use and 
less subject to error in transposition, and, therefore, 
of more practical application. The other geometric 
figures provide a greater degree of security in that 
the relative sequence of the elements comprising the 
plaintext is more completely disarranged leaving 
little positional pattern. However, due to their 
own complexity, they find little use in military 
communications. 


3-5. p Transposition Routes 


a. Jfist as the size and the shape of the matrix 
must be predetermined by the correspondents using 
a transposition system, so must the method of 
inscribing and transcribing the plain and ciphertexts. 
Depending to some degree upon the configuration of 
the matrix used, there are two general methods that 
may be followed: route, or columnar method. 

b. In route transposition, the plaintext message is 
inscribed within a matrix in the usual manner of 
writing, from left to right, top to bottom. Then to 


-~CONFIDENTIAL— 7 


(1) Simple horizontal: 


(1) (2) (3) (4) 
ABCDEF FEDCBA STUVWX XWVUTS 
GHIJKL LKJIHG MNOPQR RQPONM 
MNOPQR RQPONM GHIJKL LKJIHG 
STUVWX XWVUTS ABCDEF FEDCBA 


Alternate horizontal: 


(1) (2) (3) 
ABCDEF FEDCBA XWVUTS 
LKJIHG GHIJKL MNOPQR 
MNOPQR RQPONM LKJIHG 
XWVUTS STUVWX ABCDEF 


(3) 
GKOS VX 
DHLPTW 
BEIMQU 
ACFJNR 


(7) (8) 
JNRUWX XWURNI 
FIMQTV VTQMIF 
CEHLPS SPLHEC 
ABDGKO OKGDBA 


RVJFCA 


(4) Alternate diagonal: 


(1) (2) (3) (4) 
ABFGNO ONGFBA GNOUVX XVUONG 
CEHMPU UPMHEC FHMPTW WTPMHF 
DILQTV VIQLID BEILQS SQLIEB 
JKRSWX XWSRKJ ACDJKR RKJDCA 


(5) (6) (7) (8) 
ACDJKR RKJDCA JKRSWX XWSPKJ 
BEILQS SQLIEB DILQTV VIQLID 
FHMPTW WIPMHF CEHMPU UPMHEC 
GNOUVX XVUONG ABFGNO ONGFBA 


Spiral clockwise: 


(1) (2) (3) (4) 
ABCDEF LMNOPA DEFGHI IJKLMN 
PQRSTG KVWXQB CRSTUJ HUVWXO 
OXWVUH JUTSRC BQXWVK GTSRQP 
NMLKJI IHGFED APONML FEDCBA 


Spiral counterclockwise: 


(1) (2) (3) (4) 
APONML FEDCBA NMLKJI IHGFED 
BQXWVK GTSRQP OXWVUH JUTSRC 
CRSTUJ HUVWXO PORSTG KVWXQB 
DEFGHI IJKLMN ABCDEF LMNOPA 


Figure 8-1 gf. Matriz routes (U). 


form the ciphertext, the letters in the design are 
taken out of the matrix transcribed by following one 
of many different routes. Each route may have a 
different starting point and follow a different path 
through the matrix, with the only consideration 
being that it be orderly and fixed. Dependent upon 
the agreement among the correspondents, the use of 
routes are either fixed or varied at a given interval. 
A few typical routes which are used are shown in 
figure 3-1, and for ease in following their paths, the 
normal sequence of the alphabet is used. 

ec. Columnar transposition differs from route 
transposition in that the path of extraction is based 
upon the columns of the matrix. Again inscription 
is normally in the usual form of writing, although it 
may be varied by any route other than vertical, and 
then transcribed vertically from the cells of the 
matrix to obtain ciphertext. The sequence in which 
the columns are extracted from the matrix may be 
varied: either by following preassigned directions; 
top to bottom, bottom to top, etc.; or by the use 


of special keys which determine columnar order; or 
even by a combination of the two. Two of the more 
common vertical routes are illustrated in figure 3-2. 

d. The indication for the correspondents of the 


(1) Simple vertical: 


(1) (2) (3) (4) 
AEIMQU UQMIEA DHLPTX XTPLHD 
BFJNRV VRNJFB CGKOSW WSOKGC 
CGKOSW WSOKGC BFJNRV VRNJFB 
DHLPTX XTPLHD AEIMQU UQIIEA 


Alternate vertical: 


(1) (2) (3) 


DELMTU 
CFKNSV 
BGJORW 
AHTPQX 


AHTPQX 
BGJORW 
CFKNSV 
DELMTU 


XQPIHA 
WROJGB 
VSNKFC 
UTMLED 


Figure 8-2 (C). Columnar extraction routes (U). 


3-2 GONFIDENTIAL 


—— 


2 


use of a given transposition system (single or 
double), the type transpositions (route or columnar), 
and the specific route or key used are functions of 
the discriminant and specific key. In most cases, 
the discriminant refers to the use of a given trans- 
position system and its type, while the specific key 
refers to the specific route or key used in the in- 


‘scription and transcription processes. As required, 


either or both may appear in the message. They 
usually occur at a specific point in the message 
text, sometimes so constructed that to the outsider 
they appear as a legitimate part of the text. At 
other times they are easily recognizable for what 
they are. 


Section Il. (4) ROUTE TRANSPOSITION SYSTEMS 


3-6. S Encipherment and Decipherment 


a. The encipherment and decipherment steps in 
route transposition are based upon the use of fixed 
matrices and routes; the latter process is a reversal 
of the former. To illustrate how the system is used, 
the following steps are illustrated. The system in 
this case, to be indicated by a discriminant, is 
single route transposition. The specific key indicates 
the following elements are required. 

(1) A completely filled matrix of 5 rows and 8 
columns. 
(2) A route of inscription following an alter- 
nate diagonal, as shown in figure 3~1, route (4)—(3). 
(3) A route of transcription following an alter- 
nate diagonal, as shown in figure 3-1, route (3)—(6). 
b. Inscription of the plaintext is as follows: 


ATTACK HAS BEEN POSTPONED UNTIL 
TOMORROW TWO AM 


OS TIOWAM 
HPTNLRTO 
KAN PUTRW 
TCS EODOO 
ATABENEM 


Mor TN Ln PO 
KANPUTRW 
TCS EODOO 
ATABENEM 


MOAWT WORRO MOTLII EDUNT NOPTS 
EENPO BSAHA CKTTA 


d, Decipherment is merely a reversal of the 
preceding steps. The cipher message is inscribed 
in a 5 x 8 matrix following route (3)-(6), then 
transcribed following route (4)—(3), thus regenerating 
the plaintext. Using this system requires both 
remembering a series of rules, and following these 
rules explicitly. Any deviation in either process 
creates some difficulty in deciphering the message 
with the difficulty proportional to the error. 

e. Of all the transposition systems, route trans- 
position of this type probably offers the least 
resistance to the cryptanalyst. This remains true 


despite the apparent variability afforded by chang- 
ing the dimensions of the matrix, the routes of 
inscription and transcription, and the starting 
points. For example, observe the cryptogram just 
produced. The briefest examination would quickly 
reveal three words, ATTACK, HAS, and TOMOR- 
ROW. In all cases the plaintext would not be so 
readily identifiable, but sufficient fragments would 
occur to enable the analyst to solve the cryptogram 
with little difficulty. 


3-7. (Y) The Use of Nulls 

a. Nulls are symbols appearing in cryptographic 
texts which have no plaintext value. They are usually 
similar in appearance to the other elements of the 
cryptographic text. Nulls may be used to complete 
& matrix in transposition systems, to pad a text for 
purposes of security, or where service regulations 
require, to form groups of equal length. It is common 
to find that a transposition system provides a greater 
number of cells than letters in the message to be 
enciphered; or that the number of letters in the 
message are not divisible equally by group length. 
In either case nulls are often used. When nulls are 
used in transposition systems they must be inserted 
in the matrix at the same time as the plaintext, and 
extracted with the plaintext to form the ciphertext. 
Adding the nulls after the ciphertext has been 
generated will result in changing the sequence so 
that the message is either difficult or impossible to 
decipher. 

b. As transposition ciphers are only rearranged 
plaintext, exhibiting all the normal frequencies of 
plaintext, the letters chosen for nulls are limited. 
Letters of very low frequency, such as J, K, Q, X, 
or Z in English, are normally avoided. as their 
overuse may make them recognizable for what they 
are. High- and medium-frequency letters serve best 
as nulls, but they are limited in their placement. To 
avoid the possibility of misinterpretations or errors 
in spelling in the text proper, nulls are generally 
placed in the last positions. 

c. When nulls are employed solely for the purpose 
of making cryptanalysis more difficult. they may 
appear at any position within the message text. To 
insure the identification by concerned correspondents 


CONFIDENTIAL — - 


CONFIDENTIAL — 


nulls are usually placed in prearranged positions, 
although the placement may be random if the 
system permits. For all practical purposes, however, 
the use and placement of nulls concern the cryptog- 
rapher more than the cryptanalyst. They add to 
the length of the text to be enciphered, possibly 
induce errors, and cause the user, whose time is of 
the essence, difficulty in deciphering. Increase in 
security by their use is questionable. 


3-8. (YSpecial Cases of Route Transposition 
a. The effects of route transposition may be ob- 
tained by methods other than those previously 


shown. Two examples are reversed writing and 
vertical writing; the latter in horizontal form is 
also known as the rail-fence cipher. Both systems 
are extremely simple from the cryptanalytic view- 
point, but they illustrate that a given method of 
encipherment may duplicate the results produced 
by another method. Thus, the cryptanalyst may be 
able to solve messages accurately, yet not have 
recovered the original system that produced it. Also, 
a solution devised for one type system may Bg equally 
valid applied to another type. 

b. The procedures of reversed writing are illus- 
trated in figure 3-3 by enciphering this message: 


BRIDGE DESTROYED AS DIRECTED 


(1) Reversed retaining original word length. 


DETCERID SA DEYORTSED EGDIRB 


(2) Regrouping the words in cipher text of five letters. 


DETCE RIDSA DEYOR TSEDE GDIRB 


(3) Reversing words retaining their original length. 


EGDIRB DEYORTSED SA DETCERID 


(4) Regrouping the reversed words in cipher text of five letters. 


EGDIR BDEYO RISED SADET C, 
. Reversed writing (U). 


Figure 3-3 


c. The ciphertext produced by method (2) above 
is duplicated by: 


Inscription! BRIDG@ 5 

2 EDEST 4 

3) OY BD 3 

4 ASDIR 2 

5 E C T E D $1 Transcription 
d. The method of achieving the same message 


BURNSIDE, Falmouth, Virginia: 


text through the use of route transposition illustrates 
that, although the external appearance of the two 
methods differ, their products are the same. 

e. During the Civil War an interesting form of 
reversed writing, involving the use of phonetics 
shown in figures 3-4 and 3-5, was employed on 
several occasions. The following message, allegedly 
sent from President Lincoln to General Burnside, is 
an example: 

Washington, D.C. 


November 25, 1862 


Can Inn Ale me withe 


2 oar our Ann Pas Ann me flesh ends N.V. Corn Inn 
out wtth U cud Inn heaven day nest Wed roe Moore 
Tom darkey hat Greek Why Hawk of Abbot Inn B chewed 


I if. 


ates 
Figure 3-4 . Reversed phonetic writing (U). 


Reading the message backward with the stress on the 


phonetics the recipient reads the message as: 


If I should be in boat off Aquia Creek at dark 
tomorrow (Wednesday) evening, covld you, with- 
out inconvenience, meet me and pass an hour 


or two with me? 


A. Lincoln 


Figure 3-6 i vissis reversed phonetics (U). 


a4 GONFIDENTIAL 


. DENTIAL 


f. A system of more practical worth, when 
compared to that above, is vertical writing or the 
rail-fence cipher. The message, “BRIDGE DE- 
STROYED AS DIRECTED,” when enciphered in 
these systems appears as in figure 3-6. 


Variation is extended simply by increasing the 
length of each diagonal rail: 


Although different groups would be generated 
(BSSDR ETADE etc.), the system produces the 
same results as route transposition and is susceptible 
to the same security failures. 


BIGDS RYDSI ETDRD 
FETOF ADPCE 


(1) 


Vertical writing: 


(2) Rail-fence cipher: 


BI GODS RY DS f£ E T D 
R DE ET O EF AD RCE 


Figure 3-6 Sp. Vertical writing (U). 


Section Ill. J COLUMNAR TRANSPOSITION SYSTEMS 


3-9. (Z) General 


Columfar transposition differs from route trans- 
position in that the transcription of the plaintext 
from the matrix is based exclusively upon column 
order. One of the most common types of columnar 
transposition involves the use of a key to randomize 
the transcription of the columns. The purpose of 
columnar transposition is to introduce a greater 
degree of security than is afforded by either the 
route or straight sequential columnar methods. 
The use of a key, either numeric or alphabetic, 
provides a wider latitude for variation in the vertical 
route, yet serves as a controlling factor to coordinate 
the transposition process between several correspond- 
ents. Of primary interest to the analyst is that it 
also serves to limit the width of the matrix; the 


KEYWORD H E 
NUMERICAL KEY 6 4 


The numerical key is derived by assigning numbers 
in sequential order to the letters of the keyword in 
their alphabetic order. Thus A is assigned the 
number 1, and since A is repeated in the keyword, 
it is assigned 2 at its next position. Alphabetically 
D follows A, so it is assigned the next available 
number, 3. The process is continued until each letter 
has been assigned a number, no number being 
repeated. 

5. The method of deriving a numerical key from a 
literal key as shown above is only one of a number 
of methods, but it is the most commonly used. 
The same technique may be applied to phrases or 
to sentences so that a very long numerical key, 
impossible to remember ordinarily, may be generated 


CONFIDENFIAL— 


468-095 O- 72-3 


height then being the product of dividing the 


approximate message length by matrix width. 


3-10. Keywords and Numerical Keys 


a. A numerical key is composed of a sequence of 
numbers, either sequential or random and is used 
to control. certain cryptographic operations. To 
preclude the necessity of carrying a long sequence 
of random numbers in written form, cryptographers 
have devised a simple method of deriving such 
sequences from words, phrases, or sentences, which 
can be remembered much more easily than the 
sequence of numbers. This memory aid is known as a 
keyword or keyphrase, whichever the case may be; 
and from a prearranged key, a series of numbers 
can be derived, as shown below: 


ADQUARTERS 


1 


38 7 12 2 8 11 5 9 10 


at will. So far as the cryptanalyst is concerned it is 
not essential to know how a key was derived in a 
specific case, except when this knowledge will enable 
him to generate additional keys for the solution of 
other messages. Often, as will be demonstrated in 
subsequent paragraphs, he may be unaware that a 
literal key has been used as the basis for a numerical 
key, or if aware of this, be unable to recreate the 
true literal key by analysis of available information 
alone. 

c. Several general factors enter into the selection 
of literal keys which are of interest to the crypt- 
analyst, and which can under certain circumstances 
prove of value. 


3-5 


(1) It is usually such that it can be remembered 
easily. 

(2) Normally it contains as few repeated letters 
or words as possible. 

(3) It usually consists of one or more simple 
familiar words or phrases, which admit only one 
spelling and one order. 

(4) It should present no direct association with 
the special situation in which it is used, so as not to 
be easily assumed. 


Message 


Keyword 
Numerical Key 


Cipher Text 


3-11. (Sf Use of Keys With Completely Filled 

Matrices 

a. In keyed columnar transposition, where a 
completely filled matrix is used, the letters are 
written into a matrix, a square or a rectangle with 
nulls being added to complete the matrix or to 
provide the requisite number of characters to form 
complete groups; then transcribed vertically by 
following the sequence of columns as determined by 
the numerical key. For example, in figure 3-7, a 
message is enciphered by this method. 


REPORT LOCATION OF SECOND BATTALION COMMAND POST TODAY 


LIBERTY 
Se ae eee we oid g 
REPORTL 
OCA TON 
OFSECON 
DBATTATL 
ITONCOUMUM 
ANDPOST 
TODAYDN 


PASAN DDOTE TCPAE CFBON OROOD 


IATRI CTOOY TOOAM SDINN LHTN 


Figure 3-7 ra Keyed columnar transposition (U). 


b. To decipher such a message, a matrix of the 
proper size must first be constructéd. In this case, 
since the key contains 7 numbers and the message 
has 49 letters, the matrix must be a 7 x 7 square if 
the rectangle is completely filled. After constructing 
the matrix, the message is inscribed in it, starting 
with the first group of the message and following 
the sequence of columns indicated by the numerical 
key. Once the inscription is completed, the message 
can be read horizontally. 

c. The results produced by this method may be 
varied by one or a combination of changes in the 
keyword and in the routes of inscription and tran- 
scription. However, all things being equal, variation 
is most often introduced by changes in the key. A 
change of key on a daily basis, or for each message, 
is possible by preparing a whole list of keys for a 
given period, a different key being used in each case. 
It is also possible to designate the specific key to 
be used from a prepared list of keys through the 
use of an indicator in the message, inserted in a 
prearranged position of the message text. This last 
procedure has one disadvantage, however. If the 
indicator is erroneously transmitted, the message 
may be impossible to decipher, in which case the 
recipient must either ask that the message be re- 


transmitted or ask that the key indicator be con- 
firmed. In both cases the indicator may be revealed. 


3-12. (SB Use of Keys With Incompletely Filled 
Matrices 

a. The degree of cryptographic security of keyed 
columnar transposition is increased if the matrix 
is not completely filled, the number of cells in the 
matrix exceeding the total number of letters in the 
message. This increased security creates more diffi- 
culty for the cryptanalyst in determining the di- 
mensions of the matrix, and the corresponding length 
of individual columns once width is assumed or 
proved. Where this system is used, cells which will 
be left blank must be specified. 

b. Normally the system operates as shown in 
figure 3-8. 

c. To decipher the message the cryptographer 
must know the key and the position where cells 
will be left blank. Knowing that the key contains 
7 letters and the message 30 letters, he can de- 
termine the dimensions of the matrix to be 7 x 5, 
35 cells, 5 more than needed. Constructing a matrix 
of this size, he crosses off the blank cells and in- 
scribes the cryptogram in the remaining open cells 
in the order predetermined by the key. 


3-6 -GONFIDENTIAL 


CONFIDENTIAL 


Message: REINFORCEMENTS 
Keyword: PRODUCT 
Numerical Key: 4532716 
REQUEST 
IMMEODTIA 
TEREINF 
ORCEHEN 
T § 


Cipher Text: 


SINEU EEEQM RCRIT OTEME RSTAF NEDIM 


Figure 3-8 (C). Keyed columnar transposition with incompletely filled matriz (U). 


45 3 2 7 1 6 
oe OU 335. = 
Po ee ae 
eS os Poa N = 
Sk BOP SS 
~-~# ## # # 


d. To illustrate the importance of adding nulls in 
transposition systems prior to the transcription 
stage, figure 3-9 depicts what could occur if nulls 
were added after the encipherment process. 

e. Note that the addition of three nulls to com- 
plete the last group results in the destruction of 
the orderly sequence of the reencription process, 


KEY 4532716453271 


‘The letters are taken out in order, all those with the 


compounded by the use of keys, thus making the 
message indecipherable. The cryptographer has two 
options, ask for a retransmission of the message or 
attempt solution by eliminating the nulls, which 
requires their identification first. The former case 
provides clues for the cryptanalyst. 


3-13. (C) Variations on Columnar Methods 

A variation of columnar methods, either straight or 
keyed, may be obtained by writing the message out 
and extracting cryptographic text by decimation or 
by assigning the numerical key to individual letters, 
repeating its sequence as required. 


6 4 5 3 27 164 5 3 27 «16 4 5 
REQUESTIMMEDIATEREINFORCEMENTS 


appearance in the text. 


same number at the same time, in the order of their 


11112 22233 33444 445655 ete. 
SINEU EEEQM RCRIT OTEME ete. 


The process results in the same text as derived from 
the incompletely filled matrix illustrated in figure 
3-8. If the letters are extracted by decimation, i.e. 
every letter which occurs at a given interval, the 


results are the same as straight columnar transposi- 
tion, the width of the matrix equal to the interval 
of the decimation. 


—— 


Message: COMMAND POST LOCATED AT ROAD JUNCTION 


Matrix: ALPHABET 
Le7s23 hs 
COMMANODP 
OSTLOCAT 
EDATROAD 
JUNCTION 


Cipher Text: COEJA ORTNC OIDAA OMLTC OSDUM TANPT DNROH 


Nulls: ROH added after transcription to complete last group. 


ALPHABET 
116-7 52 3°83 
CSALOCAN 
ODNTROAR 
EUPCTIOO 
JMTONDME 
ATD 


Decipherment produces unintelligible plaintext: 
CSALOCA NODN TROAR ... etc. 


Figure 3~9 (G). Addition of nulls after enctpherment (U). 


4 CONFIDENTIAL 


CHAPTER 4 @ 
SOLUTION OF SINGLE TRANSPOSITION SYSTEMS 


Section I. go PRINCIPLES OF SOLUTION 


4-1. (Q Review of Characteristics 

a. Pfior to attempting the solution of any crypto- 
gram, the analyst reviews exactly what is known 
concerning the basic operation and characteristics 
of the system which produced that cryptogram. 
This general information, plus any foreknowledge 
of the possible contents or subject matter of the 
message, will determine to a great degree methodol- 
ogy and rapidity of solution. The general charac- 
teristics covered to this point are: 

(1) Transposition ciphers are a rearrangement 
of plaintext, therefore they will exhibit all the fre- 
quency characteristics of plaintext. 

(2) The process of encipherment consists of 
two stages, inscribing the plaintext into a matrix, 
and transcribing ciphertext from the matrix. 

(3) The routes of inscription and transcription 
are fixed, and each differs from the other. 

(4) Normally the matrix is either a square or a 
rectangle, and if the latter, not remarkably distorted. 

(5), The dimensions of the matrix are deter- 
mined by either the message length or by the length 
of message divided by key length. In those cases 
where an incomplete matrix is used, the dimension 
may be slightly larger in the vertical plane. 

(6) Nulls may be inserted to complete a matrix 
or to even group lengths, thus usually limiting their 
number. 

(7) Nulls are inserted prior to the encipher- 
ment process; accordingly their identification is not, 
except in rare cases, critical to the solution of the 
message. 

b. With these known characteristics, the analysis 
of transposition systems becomes one of initial 
identification, determination of the matrix dimen- 
sions, anagramming to recover the plaintext, and 
finally, key and route recovery. 

4-2. (A Identification 

Transposition systems as a class are not difficult to 
identify since cryptograms produced reflect the 
characteristic frequencies of plaintext. The stand- 
ard uniliteral frequency distribution, given in para- 


graph 2-13, usually suffices to identify one com- 
posed of English letters. For other languages special 
frequency distributions drawn up for them would 
serve the same purpose. As a matter of course, one 
of the first things the cryptanalyst does when 
attempting solution of any unknown system is to 
make a frequency distribution or test of the crypto- 
gram under study. 


3.9 Determination of Matrix Dimensions 


a. ce it is established that a given cryptogram 
is produced by a transposition system, the second 
step toward solution is the determination of the 
matrix dimensions. Where completely filled matrices 
are involved this is a relatively simple matter, for 
the dimensions, width times height, must equal 
message length. The only problem incurred is to 
determine which factors to select. 


For example, if the message contains 96 letters, 
possible dimensions of the matrix are: 8 x 12, 12 x 8, 
6 x 16, 16 x 6, 4 x 24, 24 x 4, or 48 x 2 and 2 x 48. 
In actual practice, the matrix dimensions probably 
would be a combination of the factors 12 and 8, 
or 6 and 16, rather than the other possibilities. 
The distorted rectangles represented by combi- 
nations of 24 x 4 and 48 x 2 produce a cryptogram 
similar to the vertical writing or rail-fence cipher 
discussed previously. In most cases the final solution 
to this problem lies in limiting the choices, and then 
eliminating incorrect assumptions by trial and 
error. 

6. Where incompletely filled matrices are used, 
an additional problem of determining the dimensions 
of the matrix is introduced. Determination may be 
based upon finding two factors which will equal 
message length plus a number, corresponding to 
the blank cells, which is not greater than the assumed 
value of matrix width. Forexample, note the sequence 
of letters, indicated by number for clarity, and the 
occurrence of blank cells in figure 4-1. 

c. Matrix 1 contains a total of 64 cells, of which 
only 60 are required, leaving 4 as blanks. Matrix 


-CONFIDENTIAL — “4 


BRERERED 
9 fo hae fs fxs [a6 
pfs fs [20 fo ee es [a 


fetal loshebrhs 
50 52 [52 ps] fps] 56 
srfsefsofool | TT | 


BEECEUEE 
olf 
fof fsx 
focelef fo 
aff ==) 
ficfofeal fiche 
fol el 
eespolet TLL 


Figure 4-1 (U). Letter sequence, incompletely filled matrices (U). 


2 contains a total of 72 cells, a surplus of 12. Follow- 
ing the normal procedure for inscription, the last 
row and the four cells at the extreme right of the 
next-to-last row in matrix 2 are left blank; and the 
last four at the extreme bottom right of matrix 1 
are left blank. In both cases, assuming the same key, 
the cryptograms produced from either matrix are 
similar in all respects to the other. 

d. Therefore, in those cases where blank cells 
occur in a matrix, a greater variation in dimensions 
is expected. However, as extra rows equal to the 
width of the matrix are of no consequence in the 
encipherment process, a certain limitation does 
exist. For example, in the case of a message of 60 
letters, matrix dimensions could be 8 x 8, 9 x 7, 
7x9, 11x 6, 138 x 5, 14 x 5, 16 x 4, 17 x 4, etc. In 
each case dimensions give an excess of 60 cells, yet 
the total number of blank cells does not exceed the 
total cells in a row. Final determination of the 
correct matrix is one of trial and error starting with 
the square and nearly-square rectangles. 


4-4, Anagramming 

a. Having determined possible matrix dimensions 
and possible column length, the analyst attempts 
recovery of the plaintext through a process termed 
anagramming, which simply returns the plaintext 
letters to their normal position within the matrix. 

b. The process of anagramming uses the follow- 
ing factors: 

(1) The column totals times number of letters 
in each column is equal to message length. Therefore, 
if the analyst’s assumption of matrix dimensions is 
correct, he can reconstruct the original columns 


simply by dividing the message in letter length 
elements that are equal to the height of the matrix. 

(2) All letters in a given column follow one 
another in an orderly fixed sequence, a result of the 
horizontal inscription, and thus cannot be changed 
without changing the length of the column. In this 
case, the sequence of the letters are not disturbed. 
Only the column in which a letter or a series of letters 
might appear is changed. 

(3) The letters that appear in a given row, 
when a number of assumed columns are brought 
together, can be changed in only two ways. First, 
the letters may be changed only by a change in 
column length. Otherwise they must remain fixed. 
Second, the sequence of their appearance in a 
given row can be changed only by the rearrangemont 
of the order in which the columns are juxtaposed; 
a change which will result in changing the sequence 
of the letters in all the rows. 

c. AS anagramming involves the spelling out of 
complete words from fragments and individual letters 
that appear at random in each row, the analyst can 
use the vowel-consonant ratio, a stable character- 
istic exhibited by all alphabetic languages. In 
English, this ratio is 40 to 60, 40 percent vowels to 
60 percent consonants. As the plaintext is inscribed 
horizontally, the vowel-consonant ratio will oceur in 
the rows of a matrix. This phenomenon then serves 
as a check of the accuracy of the assumed matrix 
dimensions. A count of vowels and consonants in 
each row is made and compared to the expected 
ratio. Should all the ratios fall well outside that 
expected, the rows may be changed, but only by 


_changing the column length, until reasonable ratios 


os GONFIDENTIAL— 


-GONFIDENTFIAL— 


appear. It must be expected that the exact vowel- 
consonant ratio will not always appear, particularly 
where such small samples are involved; but, on the 
other hand, the ratios should not be extremely 
distorted either. 


4-5. (Cy Recovery of the Key 


Recovery of the key is not essential to the solution 
of transposition systems. In fact, it is possible and 
is usually the case that when a given cryptogram is 
solved, the key recovery never proceeds further 
than the recovery of the numeric key. This is the 
literal key from which it was drawn and is either 
unrecognized or unrecoverable with the information 
available to the analyst. Where variations of a basic 


key are involved, recovery becomes possible and, in 
terms of speeding subsequent solutions of related 
cryptograms, very profitable. 


4-6. (GS System Identification 


a. System identification is always the first step 
unless the basic system is known without a doubt. 
As a matter of course, where the identity of a system 
is suspect but not assured, a test is used to confirm 
its identity. This may take time but, when considered 
in relation to the time spent in attempting to solve 
a system with completely inappropriate methods, it 
is time well spent. Prior to conducting any test, 
any element not part of the text must be eliminated 
to avoid the possibility of distorting test results. 


Message: 
VASCO UOUTE QFVRM OCSWH RRERG 
SMPET ARNTR IIERY EERON RNAMA 
ESOER ESLUR ABSZO IELFO RETON 
IRPBD UVUOEOO TDIOM TZHMI QFSSD 
DEEEW VASCO 
An examination of the message reveals a repeated key. Therefore, these groups are immediately 


group “VASCO” appearing in the first and last 
position. Although it is similar structurally to the 
other groups, its separate appearance and the posi- 
tions in which it occurs, are indicative of a specific 


eo Ufll 

now Ill 

Fo iti ; 
THUNLIII 

w ry Hl 


C 
1 


h 
& by 


oN PHL 


G 
1 


oe I 


JK 
0 0 


mon it 


~ 
A 


eal 


WI 
hb 


eliminated. Using the remaining 20 groups, a uni- 
literal frequency distribution made of the 
ciphertext, see figure 4-2. 


is 


THON 


ne) 
novull 
VD Il 
= so DHUTALIIII 
“1 w THU 
os THU 
Fo ill 
Hl 
m= il 
Om 
a 

rel ff 


Figure 4-2 (U). Untliteral frequency distribution, ctphertert (U). 


5. Comparing this uniliteral frequency distribu- 
tion with the: standard uniliteral frequency dis- 


~ = Till 


w ofl 


e olll 


fe HfL HHll 


wo my |] 
rm oil 
& Illi 


7 AHL 


BC JK 
1 00 


ee 


2 


@ = “tH ill 
@ otlll 


w roll 


tribution (based on 100 English plaintext letters) 
reveals similar characteristics, see figure 4~3. 


S 


o sot Ill 
cL | 
Hil 


w ofl 
ysl 
| 
On 

r i {I 
fo 


@ 
) 


Figure 4-3 (U). Standard uniliteral frequency distribution (U). 


The deviations that exist are not radical and can 
be accounted for by the smallness of the sample. 
The sample exhibits the same characteristic peaks 
and troughs of English plaintext, and the vowel 
consonant ratio appears very good. Therefore, the 
assumption that the cryptographic system is trans- 
position is quite safe, unless proven contrary in the 
analytic stages. 


CONFIDENTIAL —_— 


4-7. (@ Recovery of Matrix Dimensions 

a. Vresuming the system under study is a com- 
pletely filled matrix, the dimensions are easily 
determined. The combination of 10 x 10 is the most 
likely one which will provide a matrix of the proper 
size, though combinations of 20, 25, and 50 are 
possible. A matrix of 10 x 10 dictates that there be 
10 columns, each containing 10 letters. Accordingly, 


4-3 


__. CONFIDENTIAL 


the message is divided into 10-letter lengths and 


transcribed to the vertical position, each correspond- 


ing to an assumed column. Just as the ciphertext is 
originally removed from the matrix by columns, this 
process is merely a reversal of the enciphering process. 
For ease in identifying the columns during later 
manipulation, they are numbered as s they are with- 
drawn from the message. 


12 3 4 5 6 7 8 9 10 
UOSITREILIT® 
OCMINS ERDF 
USPEALLPIS 
TWERMUFBOS 
EHTYARODMD 
QRAEEARUTD 
FRRESBEOZE 
VENROSTEHE 
RRTOEZOOME 
MGRNRONOIW 


6. At this stage, if the message is enciphered by a 


123 4 5 6 7 8 
UOSTIRETII 
OCMINSER 
USPEALLP 
TWERMUFB 
EHTYAROD 
QRAEEARU 
FRRESBEO 
VENROSTE 
RRTOEZOO 
MGRNRONO 


These ratios, while not perfect, do not exhibit any 
unusual abnormalities such as rows almost exclu- 
sively composed of vowels or consonants. Further, 
note that the first row composed of 6 vowels and 
4 consonants, a reversal of the expected norm, is 
followed by a number of rows where the vowel 
count if slightly lower than normal. This is not an 
unusual condition. Therefore, there being nothing 
to disprove the original assumption as to the di- 
mension of the matrix at this stage, the anagram- 
ming can be started. 
ce. Several factors will aid the analyst in the ana- 
gramming process. Among these are the character- 
istic combinations of certain letters to form digraphs 
and trigraphs, the frequency with which they are 
used, and the types of terminology common to the 
correspondents using the cipher system. These 
factors will form the basis by which the anagram- 
ming process can be continued. 
(1) In column 10, row 1, a letter Q appears, a 
letter of low frequency usage, but when used in 


4-4 


NEMNYQEONDHS 


straight columnar route transposition, it could be 
read out of the matrix along the horizontal rows. 
Therefore, since it is unreadable in its present form, 
it is assumed that the system is keyed columnar 
transposition. The plaintext would not then appear 
without first rearranging the sequence of the columns. 


4-8, Anagramming To Recover Plaintext 

a. Before attempting to anagram, the analyst 
must examine the matrix he has constructed, par- 
ticularly the letter values appearing in each row. 
If the anagramming is to be successful and plaintext 
is to appear, each row must exhibit a good vowel- 
consonant ratio. This ratio does not have to be exact; 
the prime requirement is that it be possible. If the 
ratio is unacceptable, the analyst has but one recourse, 
to change the dimensions of the matrix in order to 
change row letter values. 

b. A check of the individual rows in the matrix 
above reveals the following vowel-consonant ratios. 


10 Vowels Consonants 
Q 6 4 
F 3 7 
S 3 7 
S 3 7 
D 3 7 
D 4 6 
E 4 6 
E 4 6 
E 5 5 
Ww 3 7 


English is, almost without exception, followed by a 
U. Scanning row 1 of all adjacent columns reveals 
a U in column 1. By placing these columns side by 
side in the order 10-1 the following digraphs are 
formed: 

Row (18) 
(40) 
(11) 
(63) 
(42) 
(02) 
(18) 
(20) 
(87) 
(00) 


SHmyhoonnwyes 
SIO Hyqogqe 


1 
2 
3 
4 
5 
6 
7 
8 
9 
0 


AM 


Comparing the digraphs so formed against those in 
table A-1, Frequency Distribution of Digraphs, the 
frequencies shown in brackets are obtained. All 
with the exception of WM, DQ, and SU are medium 
to high-frequency digraphs, which gives weight to 


a. 


the juxtaposition of these columns. The occurrence 
of WM and DQ in particular may be explained as 
word endings and beginnings. Therefore, these 
columns may be accepted and the anagramming 
process continued. 

- (2) The Q appearing in row 6, column 1 can be 
matched to the U in the same row, column 8 for 
the same reason as the preceding match. Thus the 
columns appear as: 


HOS: 28 
1 QUI 
2 FOR 
3 S UP 
4 S TB 
5 DED 
6 DQU 
7 EF O 
8 EVE 
9 ERO 
0 WM O 


The trigraphs formed by the addition of column 8 
are not unusual. In fact, FOR and EVE are quite 
common, and QUI, SUP, and ERO offer several 
possibilities for good word fragments. The next step 
then is to scan the remaining columns for a letter or 
combination of letters of significance. Another low- 
frequency letter is the letter,Z in row 9 column 6. 
It is not often used, though in military communica- 
tions it is used for the word “zero.” The trigraph 
ERO above could be combined with the Z to form 
the word ZERO. Accordingly the columns are 
juxtaposed. 


6 10 1 8 
1 EeQvUT 
2 S FOR 
3 Es. a 
4 USTB 
5 RDED 
6 AD®QU 
7 BEFO 
8 SEVE 
9 ZERO 
0 OWMO 


(3) At this point, one word (ZERO) plus sev- 
eral other word fragments emerge. SEVE in row 8 
suggests SEVEN; BEFO in row 7 may be BEFORE. 
If these initial word assumptions are valid, we need 
only find a column with the letter R and N in the 
7th and 8th row positions respectively. Checking 
the remaining columns, this combination is found in 
column 3. An 2 also is found in the 7th position of 
column 2, but as an EZ appears in the 8th position. 
it is rejected. Column 3 is then placed in the matrix 
to the right of column 8. 


6101 8 3 
1 EQUIS 
2 SFORM 
S. LoS eS Pp 
4 USTBE 
5 RDEDT 
6 ADQUA 
7 BEFOR 
8 SEVEN 
S: ZERO T 
0 OWMOR 


(4) From this point on the solution is quite 
simple. Only five columns remain to be placed, and 
sufficient word fragments appear in the partially 
recovered matrix to affect this easily. For example, 
in row 1 the fragment HQUIS must be preceded by a 
consonant; and there are only two unplaced, the & 
in column 5 and the T in column 9. Column 5 then 
is placed before column 6. 


5 610 1 8 8 
1 REQUIS 
2 NS FORM 
3 ALSUPP 
4 MUSTBE 
5 ARDEDT 
6  EADQUA 
7 SBEFOR. 
8 OSEVEN 
9 EZEROT 
0 ROWMOR 


(5) In row 1, the word fragment REQUIS 
suggests the word REQUISITION. A quick glance 
at the remaining values in row 1 of the unplaced 
columns reveals the letters J, T, 7, and O, which 
combined with the N in column 5 row 2 completes 
the word. If at this point it could be determined 
which column, 7 or 4, containing the / follows column 
3, the entire matrix could be written out. The word 
BEFORE in row 7 has yet to be completed, but here 
again the same situation is found; an /& appears in 
row 7 of both columns 7 and 4. The assumed word 
REQUISITION hints at the subject of the message. 
Considering this, the word fragment SUPP in row 3 
may possibly be the word SUPPLY, SUPPLIES, 
SUPPLIED, etc., all with the letter ZL following the 
last P. An LZ appears only in column 7 row 3, so it is 
assumed that column 7 follows column 3. If this is 
the case, the remaining columns must be placed in 
order 9—4—2 to complete the word REQUISITION, 
the N appearing at the first position of the second 
row. To confirm this assumption, the entire matrix 
is written out and the plaintext read off horizontally. 


CONFIDENTIAL 4-5 


CONFIDENTIAL 


mony beb eye 
OGNHWRADAHAHO 
SmmhOOnHWOS 
Re SyORmyqoqe 
SowmocoUwwyano 
WHSNDRYR VUE aw 
SOUR RNN 
Ary RDDOGAQSH 


SPONRWORAR A 
NEMNNEONDHNO 


d, As illustrated above, the process of anagram- 
ming results in the recovery of the key used in 
extracting the cipher message from the matrix. Only 
in those situations where the key exhibits charac- 
teristics of being generated by some recoverable 
system, either through a manipulation of the key 
values themselves or through derivation from a 
literal key, is this of significance. Usually the recovery 
of the key is left at this point. 


Section Il. Wf SOLUTION OF INCOMPLETELY FILLED MATRICES 


4-9. (J General 


The techniques of solution given previously represent 
those which are generally applicable to all columnar 
transposition systems. However, where the matrix 
is incompletely filled, a slightly different approach 
is required and is somewhat more involved. There 
are some instances where special conditions are 
present, and quick and convenient solutions can 
be reached, circumventing some of the more difficult 
process required for a general solution. In the follow- 
ing paragraphs a type of general solution is treated, 
followed by some of the special cases where a 
modified technique may be used. In all cases the 
basic method is based upon the characteristics of 
transposition systems dealt with in _ preceding 
paragraphs. 
4-10. A Solution for Incompletely Filled 
Matrices 

a. When dealing with cryptograms produced by 


ATTIT NCUYI 


CYEGR GTRNT LDHO 


Were it derived from a completely filled matrix, a 
5 x 10 or a 10 x 5 matrix is immediately assumed. 
But as an incompletely filled matrix is suspected, 
several assumptions leading to the dimensions are 
first considered. First, the product of the dimensions 
will exceed 50 cells. Second, nulls, if used to round 
out the groups, will appear in the matrix. Third, 
the cells left blank will not exceed matrix width. 
Given these generalities, the combination of 6 x 9 
or 7 x 8 appears as possible dimensions. Other 
combinations such as 4 x 13, or 5 x 11 are not be be 
rejected completely. Since the former gives a more 
proportional rectangle, it is tried first. In any case, 
the final determination of the correct matrix size, 
unless there is prior knowledge available, is largely 
a matter of trial and error. 

c. Assuming a dimension of 6 x 9, the message 
may now be broken into columns in such a manner 


this method, the most critical phase is identifying 
the system as such. If the cryptographic text 
contains an odd number of letters not equally 
divisible, it is obvious that this system is employed. 
Where the text is even or equally divisible, as is 
most often the case considering the norm of padding 
out the message to obtain groups of equal length, 
identification is more difficult and usually comes 
only after attempting to solve it as a completely 
filled matrix. If this attempt fails, it is assumed 


that it isan incompletely filled matrix. But, assuming 


that the system has been identified, the next problem 
is to determine the dimensions of the matrix. 

b. Wherever an incompletely filled matrix is 
suspected, the dimensions are assumed to be the 
factors of message letter length, plus a number of 
cells not to exceed the width of the matrix, which 
are evenly divisible. 


For example, examine the following cryptogram 
which contains 50 letters. 


ILAIE OEIIT TLINRE 


I OHMVM OPLSF 


as to fit the matrix, blank cells included. Thus, in 
a matrix of this dimension, there are two columns 
9 letters long and four columns 8 letters long. If 
the extraction is determined by a key, any specific 
column cannot be given a definite length. General 
parameters can be established based on the limita- 
tions of column length present. Any column can 
only be 8 or 9 letters long. Using this limitation, 
columns of maximum-minimum length are ascer- 
tained by decimating the message at intervals as 
shown in figure 4—4 first by 8’s, then by 9’s, starting 
at the first letter of the message. Possible columns 
thus generated can be arranged in the vertical 
position, numbered in the order of their extraction. 
The columns above represent the minimum and 
maximum lengths of any column in that particular 
position of the matrix, as determined by its position 
in the message. 


4-6 CONFIDENTIAL 


CONFIDENTIAL — 


3 
ATTIT wc uxt ILATIE ole Se © row alg 


}______2________, 
+—____4______ 


cylecr eens pee Seas 


ee eee eS TS 


2.34.5 
YEER 
AIICN 
TDL. YL 
TLTEL 
IATGD 
TILRH 
NENGO 
CORTI 
UEERO 
YICNH 
Y TM 
LV 

M 


moO ON 


id 
ay 


myoOorvOoOzR< 


fee 


Figure 4-4 t, . Determination of column length (U). 


For example, column 1 being in the first position of 
the message, must start at a known position. Thus, 
it can only be, at the maximum, 9 letters long. The 
second column may begin at the 9th or 10th letter, 
depending upon the length of the first column, and 
thus will contain 10 letters of which only 8 or 9 
represent the true column length. 

d. As these columns represent minimum-maximum 
length, a vertical movement against one another, 
as well as shifting of their relative order, is required 
to aline the rows in their proper sequence. A simple 
way of doing this is to write each column on a 
strip of paper so that it may be slipped or shifted 
as required. The extra letters appearing at the top 
and bottom of the columns can then be struck off, 
or added as required. The surest entry into a system 
is usually by way of some peculiarity of the system 
or the message, an example being the appearance 
of Q’s or Z’s in the text. There being none in this 
particular message, entry is sought through an 
analysis of digraphs produced by column juxta- 
position. Of the columns extracted, 1 and 6 contain 
the least number of letters. Therefore, since possible 


CONFIDENTIAL — 


~ 


combinations are limited, either could be used as a 
starting point. Selecting column 6, it is written 
vertically: 


YANVORTEVSS 


(1) Once a column has been selected as a base, 
the next step is to isolate possible adjacent columns. 
The problem consists not only of selecting the right 
column, but also selecting its relative vertical position 
in respect to the base column. In this process, the 
vertical relationship of the letters in any given 
column cannot be disturbed except by moving letters 
from the top of one column to the bottom of the 


4-1 


CONFIBENFAL— 


preceding column; or, from the bottom of one column 
to the ‘ \p of the next succeeding column. The letter 
Y may appear in either columns 1 or 2 in the example 
above. If in column 1, it must follow U; if in column 
2, it must precede J. Using the table of digraphic 
frequencies (table A-1), the possible identities of 
letters lying to the right of column 6 are attempted. 
The letters J, K, Q, V, and Z are noted as being 
rarely combined with other letters to form digraphs. 
Thus the V appearing in the columns represents 
either the start of a word, the end of a word, or 
probably a part of one of five common digraphs. If 
it represents the start of a word, it must still be 
part of the digraphs listed. Therefore, using this as 
an initial limitation, those letters which are most 
often combined with the V can be written to the 
right of it, underlining the letters most often used. 


AEIOT 


NHNWOLR TEMS 


Noting that similar limitations exist in respect to 
combining letters with F and P to form digraphs, 
these letters are also listed: 


es 
by 
ny 
ce) 
a | 


AELOPR 


YON VOR TEMS 


EFILOT 


(2) Using these possible combinations as a 
base, the remaining columns are scanned for these 


letters occurring at the same relative intervals. With 
the exception of the letters forming combinations 
with the letter V, only those high-frequency com- 
binations are selected for letters P and F, leaving 
the low-frequency combinations open. In some cases, 
the low-frequency letters form the correct combina- 
tion. However, it is better to start with the most 
common combinations; then, if no matches are 
found, check the low-frequency combinations. Col- 
umn | is set aside immediately as it offers no good 
combinations. Column 2 contains an J, A, and O 
sequence in the same relative positions. Therefore, 
it is considered. Columns 3 and 5 offer nothing; they 
too, are set aside. Accordingly, columns 6 and 2 are 
juxtaposed. . 


6 2 
0 
H 
M Y-_ (02) 
Voor (2) 
M 1 (09) 
0 L (sg) 
P A (14) 
L I. (7) 
S E (49) 
FO (40) 
E 
I 


(3) As a check, all digraphs formed by the - 
juxtaposition of the two columns are compared 
with those listed in the table of digraph frequencies, 
and are found acceptable as a group, since none are 
unlikely. If possible word fragments are lacking, 
and if there are no particular letter combinations 
which suggest the next letter to be added to any 
of the digraphs, the next possibility is to attempt 
to expand the digraphs to trigraphs, using tables 
B-1 and B-2 as a guide. As trigraphs, with column 
6 forming the first letter, only FOR or FOU appear 
likely. In the cryptogram, only one U appears. 
Therefore, if FO represents the first two letters of 
the trigraph FOU, only column 1 will fit, forming 
the third letter of the trigraph. Placing column 1 
to the right of columns 6 and 2, the pseudo matrix 
appears. 


0 GONFIDENTIAL 


(4) Examination of the rows reveals several pos- 
sible word bits—SEC can be expanded to SECOND, 
SECRET, SECTION and FOU to FOUR, FOUND, 
FOUL. Also considering the digraphs formed by col- 
umns 2 and 1, the possible trigraphs ING and INE 


6 2 1 

0 

H 

MYA 

VIT 

MIT 

OL 

P At 

LIN ING INE 

SEC SECOND SECRET SECTION 

FOU OUR FOUR FOUND FOUL 
EY = ~ ~ ~ 
I 


are suggested. These possible words and trigraphs offer 
a means of placing the next column. If the above 
assumptions are correct, the next adjacent column 
must contain one of the following sequence of letters, 
in the order shown: 


GGGGGGGGG EEEEEEEEE 
OOORRRTTT OOORRRTT T 
RNLRNLURRNL RNLRNLURNL 
Checking each column in turn for any of the above 3.6 2 1 4 6 
sequences, only column 4 contains a proper sequence, i “ a . 
that being GTR. Therefore, column 4 is placed next 
Graiaael " oles ee ae 
. i Vor? ¥ ££ * 
621 4 IMITED 
O TOLIG4d 
A BE TPATRO 
MYAC LLEINGET 
VIgTyY NS ECTO 
MITE RFOURE7 
OLIG E EY NM 
PATR Cc I TV 
LIN@ Y LM 
SECT (6) By rearranging columnar order, not changing 
FOUR the sequence, using column 4 as the starting point, 
EYN and by striking off the letters duplicated at the top 
I - and bottom which were generated in establishing 


(5) There being only two columns unplaced, the 


minimum-maximum column lengths, the matrix is 
reconstructed and thus completes the solution. 


9 
solution is greatly simplified; the columns must fall z - e Pi Y a 
either in the sequence 3-6-2-—1-4-5-3-6 etc., or CT IV IT 
5-6-2-14-3-5-6-2-1, etc. Establishing which is the YLIMIT 
correct sequence is done quickly by placing each strip BEDTOLI 
in the possible position in which it might appear, EE Edad 

? ROLCLIN 
slipping it up and down against the columns pre- GINS EC 
viously placed, to look for plaintext. By this method, TORFOU 
the following sequence would be quickly discovered: RHXXXX 


CONFIDENTIAL" 9 


4-11. (C) A Solution Using Literal Character- 
istics 

a. On occasion a cryptographic text will exhibit 
an outgrowth of the language used, which will enable 
the analyst to reach a rapid solution by a less involved 
process. In the English language for example, the 
use of the letters X, Q, K, J, and Z is-rather limited. 
Moreover, the use of any of these letters immediately 
suggests words common to the military. 


K Kilo Kilometer Kill KIA 
Q QU asin Request Requisition Quota 


X Xray, Axis 


Z Zulu 


Six, 
Zero 


Fix, 


Depending on the service and function of the corre- 
spondents, other words of limited use could be found. 
Similar limitations and associated words are found 
in all alphabetic languages and give a rather quick 
entry into a system. 

b. Taking one such characteristic, the analyst can 
move directly into the anagramming stage with 
reasonable certainty that as the recovery of the 
plaintext progresses, the matrix and its keys will 


J Juliett, June, July, Junction, Join fall out. 
VAAEI TZZMO HNEUE APDEF TOXIL 
YNTRT OORTS PLORO ARRON ECTZL 
REEEA RFAXI OUTER OTSEK JVPPE 
ZSDII IOERE QO0OOSJ EOLSO SYEIO 
WNILN RORUF ATUSF TIFTS SVUOC 
XWEZE LERRA DE 


Examination of the above text reveals a number of 
low-frequency letters which may be used as an entry 


= > Hill 
ow 
n all 
w vill 


so es tHE HH Il 
wn ost 


into the system. To begin, a frequency distribution 
is made, see figure 4-5. 


a» OHHH I 


_ #52 

SqeeeeruETe 

41191532325 
3 1 


Figure 4-5 (U). Transposition ciphertext, uniliteral frequency disiribution (U). 


(1) Any low-frequency letter may be used, 
but since the Q appears only once, it will be used. 
-With the Q as a center point, a sequence of letters 
is withdrawn from the message, the exact number 
of letters depending upon a presumed approximate 
size for the matrix. The message contains a total of 
137 letters indicating that its dimensions possibly 
lie in the general area of 10 x 14 to 12 x 12. Thisis 
just a guess serving only to place some limitation 
on the number of letters extracted, and to some 
degree to duplicate the determination of minimum- 
maximum column length by decimation. On this 
basis 13 letters are extracted, 6 preceding and 6 
following the letter Q, and inscribed vertically to 
form a column. 


RON 


4-10 


CGHUASSOBA 


Since there are five U’s in the cryptogram, five 
additional columns (each centered about a U, and 
of equal length) are now withdrawn from the message 
and compared individually against column 1. De- 
termination of which column should be paired with 
column 1 depends on which pair produces the most 
acceptable digraphs. In this particular case, addi- 
tional comparative basis is provided by the J which 
also appears in column 1. 


CONFIDENTIAL 


CONFIDENTIAL— 


(1) @y . @) (4) 6) 

IZ (02) IR (7) IT (00) IO (41) IT (00) 

IM (09) IF (10) IL (28) IR 27) IF (10) 

00 (06) OA (07) ON (77) OU (37) OT (19) 

EH (07) EX (07) ER (87) EF (17) ES (54) 

RN (07) RTI (30) RO (28) RA (30) RS (81) 

EE (42) EO (12) ER (87) ET (37) EV (20) 

QU (15) QU (15) QU (15) QU (15) QU (15) 

OE (083) OT (19) OF (25) OS (14) OO (06) 

OA (07) OF (083) OH (03) OF (25) OC (08) 

SP (10) SR (05) ST (03) ST (02) SX (00) 

JD (00) JO (02) JU (02) JI (00) JW (00) 

EE (42) ET (37) ES (54) EF (18) EE (42) 

OF (03) OS (14) OF (25) OT (19) OZ (00) 
Initially combinations (1) and (5) can be rejected, 12 3 4 5 6 
as the digraphs produced by the juxtaposition of the 1 2Z2OTlETI P 
columns produce impossibly low-frequency digraphs 2 £LLEEIEL EL 
(frequency shown in parentheses). Combinations 3 RS NEYO 
(2) and (4) contain a fair number of medium-fre- 4 EFORRNR 
quency digraphs. Combination (4) also has the 5 ESORTO 
digraph JJ with a frequency of zero. Combination 6 HEYRARA 
(3) has several high-frequency digraphs, in addition 7 AHEUDTR 
to a number of medium-frequency digraphs. It also 8 RIFEOR 
bas one with zero frequency, but since it occurs at 9 FOHVOO 
the top of the column it may not be a true match, 100 AWTARWN 
not occurring in adjacent rows at all. Of all the 11 X NUATE 
combinations (3) offers the best possibilities, and it _ 12 IF ISES C 
will be used as a base for further analysis. ‘i 13 OLF IPT 


(2) Assuming that the selected combination is 
the correct arrangement, the digraphs can be con- 
sidered for possible expansion. For example, the 
digraph JZ can be expanded to HJZL or WILL, 
QU can be expanded to QUE, or QUI, and JU to 
JUN or JUL, all fairly common trigraphs. A column 
to complete these trigraphs must contain one of 
the following combinations of letters in rows as 
shown below: 


LLL 


EETII 


OWNVAAPR WH 
0) 
oS 


NINEI 


By starting with the letter which precedes each of 
the six L’s found in the text, the following columns 
are pulled out quickly. 


CONFIDENTIAL — 


Of these possible columns, only the second sequence 
will complete the assumed trigraphs. Therefore, it is 
placed to the right of the two columns previously 
placed, which in turn forms a basis for additional 
anagramming. The placement of the columns, and 
possible expansions are shown below: 


Ilo 

(H/W) jae ee 8 
ONS 

(Z) ERO 
ROS 
ERY 

(RE) QUE (ST) 
OF I 
OHO 
STW (©) 
JUN (B/C) 
ESI 
ap ee? 


(3) Once an entry has been made into a trans- 
position system, the complete solution follows 
rapidly, and in most instances it is merely a mechan- 
ical process of making assumptions and then testing 
their validity by using appropriate frequency tables. 
Further progress is then made by expanding upon 


4-11 


a 


GONFIBENTIAL 


word fragments. Following this technique the col- 
umns shown below could be matched with little 
trouble. 


Kot Te OSk 
EWILET 
CEONSI 
TZEROPF 
ZEROST 
LLERYS 
REQUEST 
EROFIVE 
EROHOUR 
EAS TWO 
ADJUNCTION 
REES IX 

OFLW 
E 


(4) In addition to the many obvious words and 
word fragments in the matrix above, evidence also 
indicates the dimensions of the matrix. Considering 
the letters in the top row, they can hardly be part of 
a word in their present sequence, and they are 
repeats of letters appearing in the bottom row. 
Therefore, true column length may start in either 
the first or the second row (in the first row if the 
repeated letter is located there, or in the second row 
if the repeated letter falls in the bottom row). 
Consider also the letter H which ends the column 
starting XWE, and which appears as the last letter 


of the cryptogram. As it ends the cryptogram, it 
must be the last letter of the column in question. 
Note also that the W which ends the last column of 
the matrix is also the same W that appears in the 
start XWE. Therefore, it must belong to this column 
and not to the last column of the matrix, the XY then 
ending this column. On this basis, there are two 
column lengths; one of 11 starting with W and ending 
with #; the other starting with F and ending with X. 
Thus the F which ends column JZNR must be 
deleted. The columns ending WNIJL and _ that 
beginning JZNR# share in common the letters J and 
L. This is impossible. If short and long columns are 
11 and 12 letters or rows in length, neither column 
can contain both letters, as they would then be 13 
letters long. Therefore, they must be shared between 
the two, and to preserve the sequence of letters one 
must end WSJ, and the other start DNR. 

(5) Since the cryptogram contains 137 letters, 
the assumption of long columns of 12 letters and 
short columns of 11 letters is very good. For example, 
12K 12=144, 144—137=7, and 12—7=5; therefore. 
in a matrix with 12 rows and columns in which 137 
letters have been inscribed, there will be 4 long 
columns and 7 short. This can be confirmed by going 
back to the cryptogram and marking off those 
sequences used. Also, knowing the length of some 
columns will serve to isolate additional columns of 
the correct lengths, speeding the recovery process. 


VAAEI TZ22MO HNEUVUE APDEF TOXIL 
YUTRIT OORTS PLORO ARRON ECTSILIL 
REEEA RFAXI OUTER OTSEK JVPPE 
ZSOII ITOKERE Q00SJ FOLSO SYETIO 
WNILN RORUF HTUSF FTIFTS SVUOC 
XWEZE LERRA DE 
Figure 4-6 of Tsolation of columns in ciphertext (U). 
Counting the number of unused letters lying between of information, which will aid in further recovery 
those columns previously extracted, as underlined is that long columns appear on the left and short 
in figure 4-6, the following combination of column on the right. Accordingly the columns can be moved, 
lengths can be established. long columns to the left and short columns to the 
First, unused sequence of 45 letters=one 12-row extreme right to maintain word symmetry. 
column and three il-row columns. O F------ EwWIL 
Second, unused sequence of 24 letters=two 12-row L Too. CEON 
columns. S [------ TZER 
Third, unused sequence of one letter must be OE i ie ZERO 
assigned to either the preceding or following column. Se Sates LLE = 
Since it is unlikely that the precedin lumns i ees ae ae ae 
y preceding co 
: . HE S§------ EROF 
could start with JJOE, the O belongs to the following a ent a EROH 
column making it 12 letters in length. OP Fi tas EAST 
(6) The assumption as to column length seems W 0-42.24 ADdJU 
valid, but still there are only six identified as to N C-----=- REES 
length, three short and three long. An additional bit IX 


4-12 CONFIDENFAL 


CONFIDENTIAL 


(7) Having established the parameters of the 
matrix, and having placed the columns in their 
correct sequence, recovery of the remaining columns 
becomes quite easy, using the same methods pre- 
viously covered. In this case the many word fragments 
are readily apparent and measurably aid in the 
process. The completed matrix appears as follows, 
the keys being derived by the order in which the 
columns are extracted from the matrix. 


1 1 1 
ob 6 Te BB, 6 2 80 
OF FENSIVEWIL 
LTAKEPLACEON 
SI XJULYATZER 
OF IVEONEZERO 
STO PARTILLER 
YSUPPORTREQU 
ESTEDATZEROF 
IVEZEROZERORXA 
OURS FROMEAST 
WOODTOROAD IU 
NCTIONTHREES 
IXS IX 


4-12. (QZ) Stereotypes and Service Terminology 

a. A Characteristic of military cryptograms, par- 
ticularly at the lower echelons, is the presence of 
stereotypes and characteristic terminology common 
to military operations. These elements may occur. at 
any position in a message although those at the 
beginning and the ending are more readily identifi- 
able. These elements may be any of the following 


types: 


WHINE HOM 
NESQOWNAP 
SMS Ow SEW O MM 
By QB es OW 
QOQerBowyyny 


Message A 


ETROC NMIQI MNEGY VUNAC 
A B c 


RPO mH OY DWN 


(1) Phonetic alphabets. 

(2) Ranks, titles, unit designations, and nick- 
names. 

(3) Map reference data, grid coordinates, refer- 
ence lines, hill numbers, geographic place-names, etc. 

(4) Weapons,. caliber, short titles, model num- 
bers, ete. 

(5) The 24-hour time system when spelled out. 

(6) Addressee and signature lines. 

(7) Message reference components (such as part 
one of two parts, reference your message, etc.). 

b. These elements may be either spelled out or 
abbreviated. The above list is not all inclusive. Once 
the use of specific stereotypes and certain service 
terminology has been identified, the analyst is 
provided with an invaluable aid in the solution of 
cryptograms, particularly in the case of transposition 
systems. Not only is this of importance in ana- 
gramming, but also, in certain instances, the use of 
stereotypes can lead to the rapid solution of a num- 
ber of messages simultaneously. 


4-13. (7) Special Solutions 


a. On occasion, depending on the security conscious- 
ness of the correspondents, a series of messages are 
enciphered in a transposition system of the same 
width. If this is coupled with stereotyped beginnings 
or endings, regardless of whether or not different 
keys are used, the resulting ciphertext will exhibit 


a number of similarities which the analyst ‘can, . - 


quickly exploit. As an example of how these simi- 
larities are produced, observe the encipherment 
shown in figure 4-7. 


COOOO DAY & 

= SHOP 
OFornoevzau 
tom My hg Se 4g ty yw 


US Bn 


REAIE _FTONN CTRSO INIET Y 


D E 


Message B 


Q@IMNC NMPRS OILIC NTEFT NTFAS ETROO OODUN AOAOM O 


B E D 


Figure oe Repeated sequences, cipher message Aand B (UV). 


468-095 O-72 - 4 


A Cc 


4-13 


CONFIDENTIAL 


The repeated sequences that appear in both messages, 
underlined above, are the result of two factors: stereo- 
typed beginnings and matrices of the same width. 
Given these two factors, repetition in text will occur 
as a result of the enciphering process. Additionally, 
the number of repetitions is determined by the 
number of columns. The length of the repetition is 
determined by the number of rows occupied by the 


stereotype. The sequence in which the repetitions 
occur in the message are the result of the order of 
extracting the cryptographic text from the matrix, 
i.e. the particular key used. Thus, matrix width 
(number of columns), depth (number of rows), and 
order of extraction (key sequence) can be found. For 
example, consider figure 4-8. 


Message A 


ASOLI LBOAE WDLIR ACIEL NSAIR_IEDLS NDWND TQNIH UAOTL FMLIF 


1 2 


3 aa 5 


AMPES DBREU_SCEPV WNELOM YEODC SHCAI TIELT MNAEE IDERA 
meee. 7 


7 


Message B 


1 


QNILB TSROI RRIEP LIHVE O2YAS OLSUT 
2 


MTQBR OAUSC 


ARZEOQ LIMUI 
y 2 


IEEHT RXOLI__RSWBO DSERD EODPL TIAFS EIFAE SDEEE ZT 
~e oe 


7 


Figure 4-8 Z Stereotypes as repeated sequences (U). 


(1) -Each cryptogram contains 8 sequences which 
are repeated in the other. Therefore, 8 columns can be 
assumed, each repetition marking the beginning of a 
column. : 
(2) Message A contains 95 letters; as 8X 12= 96, 
we assume a matrix depth of 12 rows containing 
seven columns of 12 letters and one column of 11 
letters, the column beginning with IFA. Being the 
shortest column, it must appear at the right of the 
matrix. 

(3) Message B contains 92 letters; as 8X 12=96, 
we assume again a depth of 12 rows, four columns of 
12 letters, and four columns of 11 letters. 

(4) All repeated sequences, with the exception 
of ASOL are of the same length. As the longer columns 
of an incompletely filled rectangle occur on the left, 
the column beginning with ASOL is placed to the left. 

(5) As the repeats do not appear sequential in 
both messages, a different key has been used in each 
case. 

(6) The keys, which determine the order of 
extraction of the column from the matrix, are reflected 
by the order of the repeats in each message. 

(7) Row sequence, i.e. the order of the letters 
across the matrix, are similar in both matrices for the 


4-14 


stereotype; therefore, a column placement of 1 in 
one matrix can be applied to that column exhibiting 
the same repeat in the other matrix. 

b. With these generalities, two matrices can be 
constructed as follows, one for each message: 


A B 
A----- I A----- I 
S F S F 
O A O A 
L M L EB 
I P S S 
L BE U D 
B D T E 
O D A E 
A B BR E 
E R Z Z 
W E E --~-T 
D--~-- Ss 


With the parameters of the matrices established, 
anagramming can be commenced playing the re- 
covery of one column’s placement against the 
placement of columns in the other matrix. The two 
columns of each message that start with a Q and 
U respectively can be withdrawn and paired: 


GONFIDENTIAL- 


CONFIDENTIAL — 


> 
PAH OBAVWON SO 
OM DN OE HMNOAKRG 


RYO ORAn2o 
POnwedyyana 


iN 
he 


The digraphs formed by pairing the columns appear 
valid, and can be placed in the matrices. Examina- 
tion of matrix B shows only 3 columns of 11 letters 
remaining. Therefore, the pair above for matrix B 
must fit in two of those three spaces. Also, message 
B contains only 1 remaining column of 11 letters, 
that beginning with the repeated sequence HOD, 
which means that these three columns must be 
joined. Considering the letters available, the se- 
quence HQUI appears to be better than the sequence 
QUETI. As the first row, therefore, it is placed in 
matrix B. Since the column placement found for 


A 
12837465 
ALLREQUI 
SITIONS F 
ORMEDICA 
LANDCHEM 
ICALSUPP 
LIESHAVE 
BEENCONS 
OLIDATED 
ANDWILLB 
ESENTFOR 
WARDIMME 
DIATELY 


d. The methods of solving cryptograms enciphered 
by matrices of the same width, but where the stereo- 
types occur in the endings of the messages, are the 
same as those given above. The only difference is 
that since the repetitions occur in the last few rows 
of the matrices, the analyst deals with column endings 
rather than the beginnings of each column. All other 
conditions being equal, the analyst need only ana- 
gram using the bottom row rather than the top using 
essentially the same techniques as given for message 
beginnings. 


one matrix can be applied to the other, the same 
columns that start with the same repeated letters 
are also placed in matrix A, producing the following 
matrices. At this time, key values are also assigned 
to each matrix in the order of its column’s appear- 
ance in the messuge. 


A B 

1---7 465 ----7 158 
A EQUI A EQuUTI 
Ss ONS PF Ss ONS F 
0 DICA 7) DICA 
L CHEM L PLIE 
I SUPP s LBES 
L HAVE U TT ED 
B CONS T IS HE 
0 ATED A ARTE 
A ILL B R FORE 
E TFOR Z SIXZ 
WwW IMME E EROT 
D ELY 0 


ce. Using familiar anagramming techniques to 
place one column in one matrix, and then transfer- 
ring its location to the other matrix, both messages 
can readily be solved, resulting in the recovery of 
the following matrices: 


ws 


CRNDARNHRARNORAY 
YPaRaYVOWERDNNO 
BODWOHENARYHA 
MNOWGHN HS VAN aS 
yay RNQ he yoORA 
WNHODANHDHNN Soe 
CMR ARAN QaGQa 
AN by ty fy DY & By AN 


4-14. (J Solution of Messages of Identical 
Length 

a. When several messages of identical length have 
been enciphered using the same key, implying an 
equal width matrix, a solution can be obtained with- 
out recourse to stereotypes or literal patterns by 
using a process known as multiple anagramming. In 
this process, the anagramming is applied across 
several messages, rather than attempting to recover 
the individual columns of each message. This process 
is predicated on the premise that the letters of two 
or more messages which occur in the same relative 


4-15 


CONFIDENTIAL — 


position in a given matrix will undergo exactly the 
same change in position. 

6. Also used in this process are the characteristics 
of a progressive key. A progressive key is a series of 
numbers which correspond to the sequence in which 
letters can be extracted from a transposition cipher 
in order to read plaintext. The key may be divided 
into sections or sequences of numbers, each corre- 
sponding to a row of the matrix used to produce the 
cipher, and each bearing a definite relationship to 
other sequences. This relationship is exhibited by a 
one-digit difference between the numeric values of 
each sequence; the difference being minus for a 
preceding sequence and plus for a succeeding se- 
quence. Figure 4-9 illustrates this concept. The 
matrix contains both numbers and letters, the former 
corresponding to the sequence of extraction, and the 
latter to the plaintext. 


1 & 2 5 3 6 
AL Rif] ri cts 
1415 | 6 J20 J12 Jou 
E| RiY| FI] Ide 
2};16 | 7 J21 ]12 | 25 
E|AFyELAL VI Y 
3117 | 8 [22 113 126 
: N ; O| NIE 

18 23 | 14 127 


Pigure 4-9 ip. 


. Row sequences in a progressive key (U). 


c. The cipher text extracted in normal key sequence will appear as: 


AEFEIO TYEZE LIVNR RHNNI FAOLR YE 


To reflect the sequence caused by the extraction 
process, the analyst could assign numerical values 


AEFEIOTYEZELIV 
123 45 678 9 1211421 
0 1 2 8 


Plaintext could be read from this sequence of letters 
by using the progressive key: 


1-—15~-6—20-11-24—-2-16-—7-21-12-25 
3-17-8-22—13-26-4-18-9-23-14-27 
5-19-10 


Note that the progressive key is only a repeat of 
row sequences, each section of the key corresponding 
to a row of the matrix. The origin of the progressive 
key lies in the horizontal inscription of plaintext 
followed by the vertical transcription to form 
ciphertext. 

d. The relationship of each sequence of the 
progressive key is such that if the two letters repre- 
sented by key values 15-6 could be anagrammed in 
one sequence, one could logically assume the juxta- 
position of 16-7 and 17-8. Although a valuable tool, 


123 45 678 9 1211i21iéi21 

01 2 3 4 
LEPQRYTTLPUARRS 
QSNETBBUHBHRSM 
AOQOEEWOVGUCMTNI 
IOOOKHKEODNRNNNPO 
JNUOTEKUFRRCVA 


4-16 


SRMaAYN aH 


to each letter of the message in its order of appearance: 


this process does have some limitations. By con- 
tinued generation of possible juxtaposition, one 
could lap over into another sequence of the pro- 
gressive key. For example, a continued expansion of 
the key values 15-6 would soon produce the juxta- 
position of values 20-11; but note that 20-11 
appears in the first sequence. In this case it just 
happens that they, too, are juxtaposed, but quite 
often they are not associated in any manner. There- 
fore, juxtaposition by expansion not always 
infallible. As anagramming progresses, changes are 
sometimes required. Within limits, anagramming is 
very useful. 

e. Using this technique, the initial step in the 
solution of a number of messages is to superimpose 
the messages and assign to each column so formed, 
a number in the normal sequence, as follows: 


is 


Lob YP Be 2o 2222) 22 

6 7 8 9 0 1 2 3 4 5 

UEDEOETS R E_ Message A 
REDAA OA EE E_ Message B 
FRDBERES OT E_ Message C 
TTYGETITWRA_ Message D 
OONNITATI F A_ Message E 


CONFIDENTIAL 


Anagramming is started using any element of any Although the above anagrams give two doublets 
row, each representing a message; and since each is (LL and PP), generally they are acceptable and the 
inherently similar in respect to the movement of the process may be continued. It is at this stage that the 
individual letters, the process is applied to all other relationship between segments of a progressive key 
letters in the same column. Consequently, selecting come into play, for any column selected for a given 
the Q and U columns, ! and 8 of message B, as point pair should produce, by adding or subtracting one 


of departure, they may be juxtaposed and expanded to its number, a column that can be anagrammed to 
as follows, carrying along all other elements of 


: the other columns. Thus, column 17 is juxtaposed to 
columns: 
columns 1-8, columns 18, 19, 20, and 21 could be 
Lt >? ou pA rR anagrammed with the pairs 2-9, 3-10, 4-11, and 
QU 3H NB EH TR 5-12. The following diagram, illustrating the fore- 
AG OU EC EM WT going expansion of one sequence of a progress key, 
IN OR ON ON EN shows how it may serve as a check on the analyst’s 
JU NF UR OR TC assumption. 
(1) (2) (3) (4) (5) 
1-8-17 2-9-18 3-10-19 4-11-20 5-12-21 
LLE PPD QUE RAO YRE 
QUE SHD NBA FHA T RO 
AGR OUD ECE EMR WTE 
INT ORY ONG ONE ENT 
JUO NFN URN ORT TCT 
f. Further study of the message reveals that col- anagrams, all segments of the key are expanded and 
umn 19 could be anagrammed to columns 1-8; to juxtaposed: 
check this assumption and to generate additional 
(1) (2) (3) (4) (5) 
1-8-19 2-9-20 3-10-21 4-11-22 5-12-23 
LLE PPO QUE RAT YRS 
QUA SHA NBO FHA TRE 
AGE OUR ECE EMS WTO 
ING ORE ONT ONT ENW 
JUN NFI URT ORA TCT 
The trigraphs generated by the juxtaposition of the AGE T 
columns above appear to be valid, except those of INGWN 
the last segment, particularly the trigraphs YRS JUNC 


and TCI. For the moment, rather than rejecting 
them, it would be best to work with those showing 
the better combinations, in this case segments 1, 


By placing columns 13 and 14 to the second and third 
sequences, the following combinations are derived: 


2, and 3. Note that QU in the first and third segments 2-9-20-13 3 ~ 10-21-14 
are now followed by an A and £ respectively which PPOR QUES 
are likely combinations. If they are valid, then SHAS NBOM 
because of the relationship between sequenees, OURN EC ETI 
segment 2 must also be valid. Scanning all remaining OR EP ON TO 
columns in the message, including those just rejected, NFIvYV UR T A 

column 12 seems a likely candidate for matching . . 

to the sequence 1-8-19. Inscribing those columns As several word fragments are now quite plain 

the following combination is found: (artillery, requested, headquarters, received, five), 

the recovery of all the plaintext can be affected 

1- 8-19-12 easily, still generating additional portions of each 

LLER sequence on the basis of anagramming a single 

QUAR column to one sequence. When completed, the 


GONFIDENFAL. 4-17 


| oe CONFIDENTIAL — 


messages and accompanying progressive key would appear as: 
1 2 1 1 1 2 I 2 1 2 1 Tl 32. at 2 1 
142 518 92 5 3 62903 6473 «0147 «5 8 
ARTIILERYSUPPORTREQUES TED 
HEADQUARTERS HASBEENBOMBED 
MES SAGETWOFOURNOTRECEIV ED 
NOTH INGNEWTOREPORTONTODAY 
ROADJUNCTIONFIVEFOURTAK EN 
g. Nothing now remains to be done except to 11 4 22 15 1 8 19 
recover the numeric key used in extracting the 12 5 23 16 2 9 20 
columns from the matrix. Since the progressive 13 6.°2k 27 43> Jade Sy 
keys reflect columnar and row order, they are used 14 7 #25 18 


for this purpose. By setting them down to show their 
row and columnar sequence, the following matrix 
and keys can be recovered, see figure 4-10. 


Figure 4-10 (@). Recovered mairiz and keys (U). 


10 CONFIDENTIAL— 


CHAPTER 6 (C) 
GRILLE TRANSPOSITION SYSTEMS 


LA 

&-1. (€) Cryptographic Grilles 

a. Grille systems are basically transposition sys- 
tems which involve the use of two elements, a thin 
material in which perforations have been made 
according to a definite pattern, and a matrix, usually 
of ruled paper, of the same dimensions as the grilles. 
The grille placed over the matrix serves to uncover 
its celis in a systematic order, thus providing space 
for the insertion or extraction of letters, groups of 
letters, or entire words of the plaintext, thereby 
generating ciphertext. 


When the grill is superimposed upon the matrix. 
the apertures disclose cells of the matrix. There are 
eight possible positions in which the grilles may be 
placed upon the matrix as shown in figure 6-1. 


REVERSE AND ROTATE THRU 
FOUR POSITIONS (5-8) 


ROTATE THRU FOUR POSITIONS (1-4) 


Figure 6-1 gh. Simple cryptographic grille (U). 


In encrypting a message, the grille is placed upon 
the matrix in one of the eight possible positions. 
The letters of the plaintext then are inscribed in the 
open cells, following any prearranged route. The 


Section I. (C) GENERAL 


grille is then removed and a ciphertext produced 
by transcribing the letters, again following any 
prearranged route. 

&. Tf the number of letters of the plaintext exceed 
the capacity of the grille, the process is continued 
on a fresh matrix, this time the grille being placed 
onthe matrix at its next position. Thus by repeatedly 
using fresh matrices and progressively repositioning 
the grille, the entire message is encrypted. The 
several sections of the cipher letter, resulting from 
each grille placement on successive matrices, merely 
follow one another in the final eryptogram. In this 
manner it is only necessary for the correspondents 
to agree upon the initial position of the grille and 


its successive positions or placement. The example 


Plain text messece. 


Enerypted Text. 


THAYEK TAEEA ATHLE OOOBD SIIRM4 EVVNE THCSA 
LRUGO HNUOC FIER CITY ETVOC TOSTF IBIzT 
BUYRG ORADO VGIER 


Figure 6-2 &. Use of simple cryptographic grille (U). 


CONFIDED ees 6-1 


468-095 O- 72-5 


PART THREE (Sf 
MONOGRAPHIC SUBSTITUTION SYSTEMS 


CHAPTER 7 6 


UNILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS USING STANDARD 
CIPHER ALPHABETS 


Section I. QD BASIS OF SUBSTITUTION SYSTEMS 


7-1. ) General 

a. The methods of cryptography to be covered in 
this part differ from those previously presented in 
which the plaintext elements are transposed, but 
always retain their identity. In substitution systems 
the elements or textual units composing the original 
plaintext retain their relative position, one to the 
other, but not their identities. Cipher elements 
replace, or are substituted for plaintext and for this 
reason, these systems are called substitution. They 
may deal with individual letters, combinations of 
letters, or even words and sentences. When the 
cryptographic process deals with single letters, or 
combinations. less than words and sentences, the 
system is termed a substitution cipher system. 
When the process involves primarily the treatment 
of whole words, phrases, and sentences, the system 
is known as @ code system. 

b. The differentiation of systems, basically similar 
in that a cryptogram is produced by substituting 
one value for another, may seem somewhat arbitrary. 
However, the difference in the length of the elements 
directly affects the manipulation process of cryptog- 
raphy. Generally, the smaller the element, the 
better it lends itself to complex manipulation. 
Substitution systems are also further classified by 
the number of alphabets involved, and by the 
number of elements used and manipulated from 
each alphabet. A detailed definition of common 
substitution systems is found in paragraph 1—12¢. 

ce. A fundamental characteristic of monoalphabetic 
substitution, the first substitution system to be 
considered, is that each individual plaintext unit, 
one character or a number of characters, is always 
represented by the same cipher unit, again one or a 
number of characters. This rigid rule is one of the 
inherent weaknesses of this class of system, for 


cipher units must inevitably occur with the fre- 
quency of use of the plaintext equivalents, and 
analysis of the system is thereby greatly simplified. 


7-2. (U) Nature of Alphabets 


a. In the study of cryptanalytics, the dual nature 
of the alphabet becomes apparent. In order to write 
a polysyllabic language with facility, it is necessary 
to establish and maintain, by common agreement 
or convention, a national equivalency between two 
sets of elements, a set of elementary sounds, and a 
set of elementary symbols to represent the sounds. 
Theoretically, in an ideal alphabet, each symbol or 
letter denotes only one elementary sound, and each 
elementary sound is invariably represented by the 
same symbol. 

6b. The English language is written by means of 
26 simple symbols or letters which, taken together 
and considered in a sequence, constitute the alphabet 
of the language. The Dutch and German alphabets 
are similar in length, French has 25 characters, 
Italian has 27, and Russian has 31. Not all systems 
of writing are of this nature. Chinese writing is 
composed of about 44,000 complex characters, each 
representing one sense of a word. Japanese writing 
has a syllabary consisting of 72 syllabic sounds, 
which can be expressed by 48 characters, singly and 
in combination. 

c. Written plain language consists of words, i.e. 
combinations and permutations of the letters of 
the alphabet which represent visually, and call 
forth vocally, the elementary speech sounds of which 
the spoken language is composed. In the case of 
polysyllabic alphabetic languages, the principles on 
which substitution ciphers rest may be applied in 
all cases. In the encipherment of the Japanese and 
Chinese languages, these principles cannot apply 
directly to the language. They first require a 


~CONFIDENTIAL—+__ 71 


is | Example: 


conversion to other values that can be understood. 
This method of conversion and its implications will 
be demonsjrated in future chapters. : 

7-3. a and Cipher Alphabets 

a. Good cryptography demands that there exist 
at all times a definite relationship between the plain- 
text and the cipher values. How this relationship is 
developed is determined by the particular system, 
but if it does not exist and is not constant, de- 
cryption of the message enciphered by that system 
is an impossibility. This relationship is brought 
about by the construction of a cipher alphabet. 
The primary difference between a cipher alphabet 
and a normal alphabet is that in the former the 
elementary speech sounds are represented by char- 
acters other than those used in the normal alphabet. 
There is no real limitation other than practicability 
on what these characters may be. 
letters, figures, signs, symbols, or even a combina- 
tion of any one of these. 

6. A cipher alphabet is an ordered arrangement 
of the letters of a written language and the charac- 
ters which replace them in the cryptographic process 
_ of substitution. It consists of two components, a 
plain component and a cipher component. The 
plain component is the normal alphabet of that 
language, in which the letters of the plaintext are 


“. found. The cipher component is the sequence of 


characters from which the cipher equivalents are 
. drawn. For brevity and for clarity, a letter of the 
plain component is designated by suffixing a small 
“pn” to it, and a letter of the cipher component 


They may be - 


’ process 


designated by suffixing a small ‘‘c” to it. Thus Ap 


means A of the plaintext, and Xe means X of the 
ciphertext. The expression Ap=.Xc means that A of 
the plaintext, or plain component, is represented by 
& in the ciphertext, or cipher component. 


7-4. (CF Standard and Mixed Cipher Alphabets 


a. The plain component of « cipher alphabet is a 
normal alphabetical sequence, an alphabet where 
letters represent their commonly associated speech 
sounds and which appear in their normal order. 
This normal sequencing of the plain component is 
the norm. If the plain component is omitted, it is 
understood to be the normal sequence. The sequence 
of the cipher component, which may be cither 
standard or mixed, determines the classification of 
the cipher alphabet. 

b. Standard cipher alphabets are those alphabets 
in which the cipher sequence is the same as the 
normal sequence. For obvious reasons, a standard 
cipher alphabet must eithe be reversed in direction 
or shifted from its normal point of coincidence with 
the plain component; otherwise, Ap would equal Ac 
and all succeeding letters would equal themselves. 

ce. Mixed cipher alphabets are those alphabets in 
which the cipher component no longer demonstrates 
the normal sequencing in part or in whole. Rather 
it is disarranged by either some systematic process, 
an example of which will be treated later, or is 
generated by some arbitrary and unmethodical 
which results in a completely random 
sequence. 


Section Il. oh UNILITERAL MONOALPHABETIC SUBSTITUTION 


7-5. (A Standerd Cipher Alphabets 


a. If a message is enciphered, letter for letter, by 
using one cipher component, the resulting crypto- 
gram is said to be enciphered by a uniliteral (one- 
unit) monoalphabetic (one-cipher alphabet) cipher. 
: A standard cipher alphabet used for this purpose is 
of two types, a direct standard or a reversed standard. 


Example: 
P ABC 
C VWX. 
Key Ap=Ve. 


b. Reversed standard cipher alphabets also contain 
normal plain and cipher sequences except the latter 


H K 
C F 


ms 


I J L 
DE G 


P ABCD IK L 
F ED 


N 
I 


MN 
ona 


In direct standard alphabets, both the plain and the 
cipher sequence are normal alphabets, i.c., letters 
follow one another in normal sequence and are 
individual from left to right. Only their points of 
coincidence are shifted to the right or left of the 
normal point of coincidence. 

OPQRS UVWX Y Z 
JSJKLM ne POR 2 Oo 


sequence is inscribed backward, from right to left. 


QRSTUVWXYZ 
Y ee UTS RQP 


be 


P 
Z 


(CONFIDENTIAL— 


~. CONFIDENTIAL — 


c. Because of the difference in the direction of the 
sequence in the two alphabets, the number of 
possible cipher alphabets produced by each method 
differs. Where direct standard cipher alphabets of 
26 characters are moved against one another, there 
are only 25 combinations which are different, the 
26th being a repeat of the first, ie. Ap=Ac. In 
reverse standard cipher alphabets, the number of 
possible combinations equals the number of letters 
in the alphabet, as the direction of the sequences 
provides no one point of coincidence where the 
whole alphabets are exactly the same. 


7-6. (Reciprocity of Standard Alphabets 


a. The reversed standard cipher alphabet illus- 


P ABCDEFGHIJIKLM 
C PONMLKJIJJTIHGFED 


Juxtaposition at every second interval produces two 
equal identities, and juxtaposition at even intervals 
does not produce identities. Note also that the two 
identities occur at an interval of 13 letters. Both of 
these numbers, 2 and 13, may be recognized as the 
factors of the number of letters in the English 
alphabet (26). Other alphabets of different length 
also exhibit this characteristic, the points of juxta- 
position producing identities and the distances 
between identities determined by their factors. 


b. A reciprocal alphabet which provides complete 


trated above is also a reciprocal alphabet, i.e. the 
equivalents show reciprocity and are reversible. in 
pairs. For example, Ap=Oc and sle=Op, but note 
also that Hp=He and Up=Uc. The reciprocity, 
and the identities shown, are a result of the method 
by which it was formed. Reciprocal alphabets may 
be formed by juxtaposing two alphabetic sequences 
which are identical, but which run in different direc- 
tions. The occurrence of equal identities is dependent 
upon the point of juxtaposition. In the alphabet 
above, le coincides with Op, the 15th letter of the 
alphabet. In the example below note that le is 
moved to a point below Pp. Further note that equal 
identities no longer occur. 


NOPQRSTUVWXYZ 
CBAZYXWVUTSRQ 


reciprocity and no identities may be produced in 
one of two ways: 

(1) By arbitrarily constructing a reciprocal 
alphabet by the random assignment of values in 
pairs. For example, Ap is made to equal Ke: then 
Kp is made to equal Ac. In such an alphabet, the 
two components thus constructed cannot be slid 
against one another to produce additional reciprocal 
alphabets. 

(2) By juxtaposing ao sequence of an even 
number of characters against the same sequence 
shifted exactly halfway to the right or left as below. 


ABCDEFGHIJKELMNOPQRSTUVWXYZABCDEFGHI J K LMNOPQRSTUVWXYZ 
ABCDEFGHIJKLMNOPQRSTUVWXYZ 


Key Np=Ae 
Ap=Ne 


c. Reciprocal alphabets are inverse alphabets, 
since they may serve either as enciphering or de- 
ciphering alphabets. 


7-7. ( Method of Encipherment and Decipher- 
ment 


a. When a message is enciphered using a uniliteral 
monoalphabetic substitution system, one plaintext 
value is replaced by one ciphertext value. For 
example, using the cipher alphabet of paragraph 
7-5a, the following message can be enciphered 
(fig. 7-1): 


CONFIDENTIAL ~ ae 


468-095 O- 72 -6 


CONFIDENTIAL 


Message: 

Enciphering alphabet: Ap = Vc 
P ABCDEFGHIJKLM 
C VWXYZABCDEFGH 


Ne 


Letter for letter encipherment: 


LISTENING POSTS REPORT TANK MOVEMENT 


Q 
L 


ate 
yc 
oO < 
HK 
cn 


OP 
JK 


LISTENING POSTS REPORT TANK MOVEMENT 
GDNOZIDIB KJNON MZKJHMO OVIF HJQZHZIO 


Cipher text rearranged into five-letter groups, indicator. 


and nulls added: 


Z2YZYZ GDNOZ IDIBK JNONM! ZKJMO OVIFH JQZHZ 10XXX 


Figure 7-1 (C). Monoalphabetic encipherment (U). 


b. The procedure for decipherment is the reverse 
of encipherment. Using the indicator, the cryptog- 
rapher constructs the cipher alphabet, and since it 


Deciphering alphabet: 
C ABCDE 


The message deciphered: 


is nonreciprocal, he rearranges it on the cipher 
sequence for ease in deciphering. 


QRSTUVWXYZ 
VWXYZABCODE 


GDNOZ IDIBK JNONM ZKJMO OVIFH JQZHZ IO 
LISTE NINGP OSTSR EPORT TANKM OVEME NT 


Message rewritten into word length: 


LISTENING POSTS REPORT TANK MOVEMENT 


7-8. cf Use of Monoalphabetic Ciphers 


a. Because of the extreme simplicity of uniliteral 
monoalphabetic substitution in general, and direct 
or reversed standard cipher alphabet in particular, 
its use for practical purposes is quite limited. Solu- 
tion of these systems is generally very easy, involv- 
ing two basic methods of analysis, one based entirely 
upon a frequency distribution and the other based 
upon a quicker mechanical process. The analysis 
and solution of messages enciphered by mixed- 
cipher sequences 


tedious, but not impossible. Again, the practical 
use of this type monoalphabetic substitution is also 
limited. 

b. For the cryptanalyst, the study of these sys- 
tems is important not from the likelihood that he 
will encounter them in use, but from the basic 
techniques and skills he will acquire. Moreover, the 
basic principles of the operation of the system, and 
the method of its analysis, are incorporated and 
expanded in the more advanced and complicated 
manual systems he may encounter. 


may be somewhat involved and 
Section Ill. / SOLUTION OF UNILITERAL MONOALPHABETIC CIPHERS USING 
STANDARD CIPHER ALPHABETS 


7-9. CS Basis for Solution Using a Uniliteral 
Frequency Distribution 
a. The solution of uniliteral monoalphabetic ci- 
phers where standard alphabets are used follows 
directly from two factors. 
(1) The fundamental characteristic is the one- 
for-one substitution. 


1-4 


(2) The sequence of the letters of the cipher 
component is merely displaced if it is a direct 
standard or, if it is a reversed standard, it is re- 
versed and displaced. Because of this, a uniliteral 
frequency distribution of a cryptogram produced by 
standard cipher components will show crests and 
troughs whose relative spatial position and vertical 


dimensions will be the same as a uniliteral fre- 
quency distribution for the plaintext of that 
cryptogram. 

b. If the cryptogram was enciphered by a re- 
versed standard alphabet there will be one excep- 
tion to the exact spatial correspondence between 
the two frequency distributions. That is, the pro- 


Message: 


gression of the successive peaks and troughs will be 
in opposite directions. To observe this, note the 
plaintext messages and their accompanying cipher 
alphabets, cryptograms, and uniliteral frequency 
distributions in figures 7-2 and 7-3. 

(1) Encipherment by a direct standard cipher 
alphabet. 


ENEMY ATTACKING ALONG ROUTE ONE WITH ESTIMATED INFANTRY 


BATTALION SUPPORTED BY TANKS FORWARD POSITIONS OVERRUN 
REQUEST IMMEDIATE REINFORCEMENT 
Direct standard cipher alphabet: Ap = 7c 
P ABCDEFGHIJkKLMNOPQ TUVWXY a2 
C TUVWXYZABCDEFGHIYG MNOPQRS 
Ciphertext: 
XGXFR TMMTV DBGZT EHGZLZK HNMKH GKPBH 
AXLMB FITMXW BGYTG MKRUT MMTEB HGLWNT 
ITHKMX WURMT GDLYH KPTKW THLEM BUGLE 
OXKKN GKXIN XLMBF FXWBT KMXKKB GYHKYV 
XFXGM 
Uniliteral frequency distribution - plaintext 
= = — = 
= = = =F ~#_ =< 
ABCD ie HIJK a 4 OPQ ia aia XY Z 
9-22 4163219 O'S So 5 12-11. 3:°2'10 6-15 4 1-26. 3°0 
Total 125 
Uniliteral frequency distribution - ciphertext 
zi =. z : z 
= z= 2. 2_ = _ £ 
ABCDEF G HIJ KL MNOPQRSTUVW XYZ 
190° 2°2"5 1212.3 2.106. 15 bis 2 03 -0:9 2 2-416 3 2 
Direction of progression Total 125 


| _Foint of 
coincidence 


Figure 7-2 g . Encipherment by a direct standard cipher alphabet (U). 


—GONFIDENFHAL— 


7-5 


(2) Encipherment by a reversed standard cipher alphabet. 
Message: 


TANK COMPANY MOVING UP IN SUPPORT HOLD THE PRESENT POSITION 
AFTER ONE SIX ZERO ZERO DISENGAGE AND FALL BACK OW BLOCKING 


POSITION AS SITUATION PERMITS 


Reversed standard cipher alphabet: Ap = He 
P ABCDEFGHIJKLM : OPQRSTUVWKYZ 
C MLKJIUHGFEDCBA YXWVUTSRGPOR 
Ciphertext: 
TMZCK YAXMZ OAYRE ZGSXE ZUSKX YVTFY B&ITFI 
XVIUVI ZTXYU ETEYZ WHTIV Y2@TUe PHIVY NIVYS 
EUVIZG MGIMZ JHUBB LMKCY ZLBYK CEZGX YUETE 
YZMUU ETSMT EYZXI VAETU 
Uniliteral frequency distribution - plaintext: 
= = = #2 #= _=z 
ABCD E F GH IJKLM N OPQ@RS TUVWXYZ 
923310242120343131480691l0310112 
125 
Uniliteral frequency distribution - ciphertext: 
= = = Z2=._ =2 2 
SSS 4-253 = 2e==-27=—_ 0. _= 2#2E= 22 
ABCD EFGH ITI KLHNOPQRS TUVWK Ya 
3° 3-0 1282 42 103 3°2-9..2 2.1 O23 109 6 OS a rs 
<< 


Direction of progression 


— 


Figure 7-3 (C). Enctpherment by a reversed standard alphabet (U). 


Point of coincidence 


c. In the preceding examples, several points should 
be noted. The spatial relationship of peaks and 
troughs within either cipher component remains 
constant, differing in the points of coincidence and 
the different directions in which the order of their 
progression may lie, relative to the plain compo- 
nents. These differences are purely mechanical, due 
only to the point at which the alphabets are juxta- 


1-6 


posed and the direction of their inscription. Another 
difference, which will be shown only when the 
frequency distribution of the ciphertext is com- 
pared to an expected normal uniliteral frequency 
distribution, is that a variation in the order of the 
high-frequency letters occurs. This is a result of the 
construction of the plaintext and in no way in- 
validates the frequency distribution or its use. 


CONFIDENTIAL 


CONFIDENTIAL — 


System Identification and Recovery of 
The Cipher Alphabet 


a. In practice, the identification of a given cryp- 
tographic system as being uniliteral monoalphabetic 
substitution, based on a direct standard cipher 
alphabet and the recovery of the plaintext values 
of the cipher sequence of that alphabet, involves 
one and the same process, based upon the charac- 
teristics of standard cipher alphabets and the nor- 
mal uniliteral frequency distribution. A frequency 
distribution made of a cryptogram produced by this 
type system will show the characteristic peaks and 
troughs of a normal uniliteral frequency distribution 
for the plaintext, except peaks and troughs will not 
correspond and the direction of progression of the 
sequence may be reversed. Identification of this 
system’s use, and the recovery of the plaintext 
values of the cipher sequence, lie in fitting the 
uniliteral frequency distribution of the ciphertext 
to a normal uniliteral frequency distribution. This 
is known as “fitting the distribution to the normal.” 

b. Identification and recovery of the plaintext ts 
then simply a matter of identifying the plaintext 
value of two or more cipher letters and the use of 
these values to determine the direction of progres- 
sion of the cipher sequence relative to the plain 
sequence. The identification of a cipher letter, 
determining its associated plaintext value, is based 
upon its frequency of occurrence relative to all 
other letters of the cipher sequence. For example, 
the value of a high-frequency cipher letter immedi- 
ately is suspected as one of the normal high-fre- 
quency letters (E, T, N, R, O, A, I, S). By assuming 
the values of several high-frequency cipher letters. 
a base can be established to correlate the peaks and 
the troughs of the ciphertext distribution to those 
of a normal uniliteral frequency distribution. 

c. In fitting the actual distribution of the cipher- 
text to the expected norm, two functions must be 


7-10. 


considered. First, correspondence of values will not 
necessarily be exact regarding frequencies of oceur- 
enee. For example, the normal order of occurrence 
for the high-frequency plaintext letters is E, T, ON, 
R, O, A, I, S. But, note that the frequency of these 
same letters in the cryptogram in paragraph 7-96(2), 
in their order of occurrence, is O, N, I, E, T, A, 5S. 
R. Second, although frequency of oecurrence may 
vary, the spatial relationship between the high- 
frequency letters, and all letters, will remain con- 
stant. Because of the former fact, the point of co- 
incidence of the two sequences may be in question. 
However, this can always be resolved by considering 


the spatial relationship of peaks and troughs. 
Considered as a group, their correspondence of 
frequency between sequences should always be 


relatively close. 

d. In the final analysis, the accuracy of identifica- 
tion and recovery of the cipher alphabet hinges on 
the consistent substitution of the plaintext values for. 
the cipher character in the cryptogram resulting in 
intelligible plaintext. If this is not the case. no 
matter how close the approximation between actital 
and expected ‘requencies, or how well the fit ts, 
only two pos-wilities exist. First, the closeness of 
the fit is pure coincidence and another equally good 
fit can be obtained from the same data. Second, the 
eryptogram involves something more than simple 
monoaiphabetic substitution by means of single 
standard cipher alphabet. 

7-11, Solution Using a Uniliteral Frequency 
Distribution 

a. Essentially, the method of solution is) an 
attempt to fit the distribution of the ciphertext to 
the expected normal distribution. Accordingly, the 
first step is to prepare a uniliteral frequeney distri- 
bution of its ciphertext. Using the message in figure 
7-4, the distribution can be derived. 


YICAX UBANY XACNJ 8C/AW BUXYN BXOYA 


XBYNL CQRUU VRWilM JWELX ENANH KHBCA 


XWPYX RWCBW NJALA 


Z272_.  _ =_= 


EFGHIdJ KL? 


9871 


Figure 7-4 (C). 


NBCDO 


z _=_ 
~=— 


=_222 


PQ@RSTUVWKY Gz 


iO 


To01l03122W211300416860 


Uniliteral frequency distribution, substitution ciphertext (U). 


CONFIDENTIAL 


7-1 


(1) If there is any question as to the system 
involved in the production of this cryptogram, the 
uniliteral frequency distribution above should serve 
to resolve it. First, substitution, rather than trans- 
position is indicated by the fact that normal low 
and medium-frequency letters in this distribution 
are high in occurrence. Were it transposition, where 
values are unchanged, there would not be this 
reversal of frequency characteristics. Second, uni- 
literal monoalphabetic substitution is suggested by 
the peaks and troughs, shown by the distribution, 
which do not correspond to their normal positions 
relative to the alphabet. This further suggests a 
displacement of the points of coincidence between 
the plain and cipher sequence. If nonmonoalphabetic 
substitutions are involved, the peaks and troughs are 
suppressed. 

b. Solution of this type system depends upon 
assuming the plaintext value of one or more cipher 
letters, establishing the direction of progression, and 
attempting to produce intelligible plaintext as the 
final text. Comparing this distribution to a normal 
distribution, certain similarities and dissimilarities 
are observed as shown in figure 7-5. 

(1) Note that the pattern of peaks and troughs 
in the normal distribution have a specific spatial 
relationship, the highest crest over the letters A, 
E, I, N, R, S, O, and the toughs marked by T, B, 
G, J, K, P,Q, U, V, W, X, Y, and Z. Note also that 
the letters R, S, T, and U combined, form a plateau, 
as does L, M, N, and O. In horizontal distances, 
A is separated from E by three letters, E from | 
by three letters, I from N by four letters, and N 
from T by five letters. 


P ABCDEFGHtIJKLMN 


C JKIMNOPQRSTUYV 


(4) As this alphabet is not reciprocal, ie. Ap=Je 
but Ac does not equal Jp; the values must be inverted 
to form a deciphering alphabet. That is, the cipher 


For example: 


C ABCDEFGHIJSJKLM 
P RSTUVWXY2ZABCOD 
(5) Using the above deciphering alphabet. 


the cryptogram can now be deciphered, success 
indicating that all previous assumptions are correct. 


Pty Tv TT UT 
Pi AY 


ae ee CRY 
NIZA 
POPPE ryt rarer es 


. Identification of ciphertext values by 
comparison (U’). 


Figure 7-5 


(2) Examination of the distribution “prepared 
from the ciphertext reveals a‘similar spatial pattern. 
but one which is located above different letters. 
Note that a peak located at J is followed by another 
at NV, separated by three spaces; another is located 
at ?, again a three space interval; U also represents 
a peak, at an interval of two spaces, and is followed 
by a plateau at W, X, and Z. 

(3) Considering the cyclic nature of the alpha- 
bet, Z followed by A, and assuming that the progres- 
sion of the pattern in the ciphertext’s distribution is 
to the right, the two patterns can be alined by 
shifting the cipher sequence to the left until J 
cipher coincides with A plain. 


OPQRS TUVWHRY Z 
rf 


"NX YZABCDEF GH 


component placed in alphabetic order with the plain 
component below it. 


Oh PO OR SF VOW ALT 
FGHIJKUMN OPQ 


If failure results, the analyst reexamines the distri- 
bution attempting to determine the correct point 
of coincidence between the two alphabets. 


YJCAX UBANY XACNJ BCNAW BUXYN BXOYA 


PATRO LSREP ORTEA STERN 


SLOPE SOFPR 


AXABYNLIL CQRUU VRWNM JWMLX ENANM KHBC A 
OSPEC THILL MINED ANDCO VERED BYSTR 
XWPYX RWCBWNJALA NBCDO 
ONGPO INTSN EARCR ESTUF 


‘ PATROLS REPORT EASTERN 


SLOPES OF PROSPECT HILL 


MINED 


AND COVERED BY STRONG PONNTS NEAR CREST 


7-8 


-CONFIDEN FAL 


GONFIDENFIAL 


c. In the example above, a direct standard cipher 
alphabet is used in enciphering the plaintext. Had 
the cipher alphabet been a reversed standard, the 
same methods of analysis would have been fully 
applicable, the only difference being that the pro- 
gression of the relationships of peaks and troughs 
in a distribution of the ciphertext.would be in re- 
verse order as well as offset. To aline this distribution 
to the normal, it is then inscribed in reverse order 
after determination of the point of coincidence. 
Further, a slight variation exists in the final de- 
ciphering text. As reversed standard cipher alpha- 
bets are partly reciprocal, the construction of a 
deciphering alphabet is not always required. 

7-12. (ZYSolution by Completing the Plain 
Component 
a. The foregoing method of solution involves the 


construction and study of a frequency distribution - 
is & means of recovering the plaintext. There is 
another method, applicable to direct standard 
alphabets and to reversed standard alphabets with 
a slight variation, which is much more rapid. As 
this system is purely mechanical, it does not involve 
the construction of a frequency distribution. The 
principle underlying this method of analysis is 
based upon the inherent characteristics of uniliteral 
monoalphabetic cipher alphabets, where direct stand- 
ard or reversed standard alphabets ure used as the 
cipher sequence. The key element in both cases is 
an orderly sequence of values present in both the 
plain and cipher sequences. 

b. The significance of this characteristic is seen 
in the following cipher alphabet. 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 
C SJSKELMNOPQRSTUVXWYZABCDEFGEHI 


(1) Note again that the cipher alphabet was 
produced by juxtaposing two normal alphabets, 
the lower or cipher sequence being displaced 9 
letters to the left until Ap=Jc. This relative degree 
of shift is equal in all cases as long as the sequence of 
the letters in the alphabets are not disarranged. For 
example, note that there is a 9-letter difference 
between Be and Ke, Cp and Lp, etc. As-a direct 
standard cipher alphabet is being dealt with, there 
are only 25 possible positions in which the two 
alphabets may be juxtaposed to produce a cipher 


alphabet. The 26th position, Ap=-te, clearly gives 
only plaintext. Where this sytem is used then, only 
one of the 25 possible positions can be correct. 

(2) The alphabet above could be slipped 
through all 25 possible positions, from Ap=Bc to 
Ap=Ze, checking each for its ability to decipher a 
méssage. This is time consuming. Instead. the 
sequence of the letters themselves can be used. 
Note the encitpherment of the following plaintext. 
first by the cipher alphabet above, and then by a 
similar alphabet where Ap=Ke. 


CONTACT MADE WITH ENEMY Plaintext 
LXWCJIJLC VIMN FRCQ NWNVG Cipher Ap=Je 
MYXDKMD WKNO GSDR OXOWT Cipher Ap=Ke 


(3) In the example above, the sequence of 
letters in the columns is formed by superimposing the 
ciphertext progress, following each progressive dis- 
placement of point of coincidence. Therefore, given 
the cryptogram, a solution can be obtained simply 


by inscribing alphabets vertically in sequential 
order, using as the starting point each letter of the 
ciphertext as demonstrated in figure 7 6. In cffect, 


this process duplicates the possible ciphertext 


derived from all 25 positions. 


-GONFIDENTIAL— 19 


CONFIDENTIAL 


Example: 


GXKGA TIKKS 
HYLHB UKLYT 
IZHIC VLMZU 
JANID WhilAY 
KBOKE XIIOBW 
LCPLF YOPCX 
HDQUG ZPQDY 
JERMH AQREZ 
OFSOI BRSEA 
PGTPJ CSTGB 
QHUQK DTUHC 
RIVRL EUVID 
SIWSH PYWIE 
TKXTW GWXEKF 
ULYUO HYYLG 
VEZVP I2ZZiH 
WHAWQ JZANI 
XOBXP KABOJ 
YPCYS LBCPK 
ZQD2T HCDQL 
AREAU_NDERM 
BSFBV OFS 
CTGCW PFGTO 
DUHDX QGEUP 
EVIEY RHIVQ 
FWIEZ SIJWR 


UXZGK LOXKD Cipher text 
VYAHY [MPYLE 
WZBIZ NQZHF 
XACJA ORANG 
YBDKB PSBOH 
ZCELC QTCPI 
ADFHD RUDQJ 
BEGNE SVERK 
CFHOF TWFSL 
DGIPG UxGTi 
EHJQH VYHUN 
FIKRI WZIVO 
GILSY XATWP 
HKHTK YBKXQ 
IINUL ZCLYP 
JHOVI ADHZS 
KNPWY BENAT 
LOQKO CFOBU 
MPRYP DGPCV 
NQSZQ EHQLUW 
ORTAR FIPREX Plain text 
PSUBS GJSFY 
QTVCT HKTGZ 
RUWDU ILUHA 
SVAEV JuVIB 
TWYFW KIIWIC 


Figure 7-6 (C). Solution by completing the plain component, direct standard cipher alphabet (U). 


c. In those cases where a reversed standard 
cipher alphabet is used, a preliminary step is required 
to form the base for the projection of the vertical 
alphabetical sequences. This is required because, 
although a sequence is present in the ciphertext, the 


mechanics of the system are reversed. For example. 
with the following message, a base can be established 
as shown in figure 7-7. Then each column can be 
completed to recover the plaintext. 


7-10 CONFIDENTIAL 


CONFIDENFIAL— 


Message: 


MN 


A 
Z NM 


BCDEFGET L 
YXWVUTSR 6) 
CIHDC 


‘GHZWB 
HIAKC 
IJBYD 
JKCZE 
KLDAF 
LHEBG 
MNECH 
NOGDI 
OPHES 
PQIFK 

MSRANM = QRIGL 

NTSON RSKHI 
OUTPO: STLIN 


CIHDC 
DITED 
EKIFE 
FLKGF 
GMLHG 
HNMIH 
LOHT LI 
JPOKS 
KQ@PLK 
LRQUL 


SKWHV 
PLXIW 
UMY SX 
VNZKY 
WOALG 
XPBIA 
YQCNB 
ZRDOC 
ASEPD 
BIFQE 
CUGRF 
DVHSG 
EWLTH 


PQRS U 
KJ IHGFED 


RFOKB 
SGPLC 
THQHD 
UIRVE 
VISOF 
WKIPG 
ALUQH 
YMVRI 
ZNWST 
AOXTK 
BPYUL 
CQZVi 
DRAWI 


XRSWX TSADY HPDSE IULPY 


T VW 


HZWB SKWHV RFOXKEB 


Cipher text 


Plain text 


PXJUI 
GYKVS 
HZLWK 
TAMXL 
JBUYE 
KCOZN 
LDPAO 
MEQBP 
ERCQ 
OGSDR 
PHTES 
QIUFT 
RIVGU 


PVUQP TUIMJO 
QWVRQ UVNKP 
RXWSR VWOLQ 
SYXTS WXPMR 
TZYUT XYQNS 
UAZVU YZROT 
VBAWV ZASPU 
WCBXW ABIQV 
XDCYX BCURW 
YEDZY CDVSX 
ZEEAZ DEWTY 
AGFBA EFKUZ 
BHGCB FGYVA 


FSBXO 
FTCYP 
GUDZQ 
HVEAR 
IWFBS 
JXGCT 
KYHDU 
LZIEV 
MATFW 
NBKGX 
OCLHY 
PDMIZ 
QENTA 


Figure 7~7 p. Solution by completing the plain component, reversed standard cipher alphabet (U). 


d. Using the foregoing method, when the letters 
of a cipher alphabet are known sequences, con- 
siderable time and effort can be saved. In some cases 
this prior knowledge is the only possible means of 
solving very short cryptograms that might other- 
wise be unsolvable. The essential point in any case 
is that the sequence of the letters used must be 
established. Even mixed sequences can be handled 
in exactly the same way. If, however, the sequence 


is unknown, methods to be covered later must be 
used. Generally, since this method is so easy, it 
should be a first step in those cases where the 
cryptogram is obviously a substitution cipher in 
monoalphabetic terms. First a direct standard 
alphabet should be tried, and then a reversed 
standard alphabet should be tried. If both fail, a 
logical assumption is that the cryptogram in ques- 
tion involves a mixed cipher alphabet. 


7-11 


CONFIDENTIAL 


CONFIDENTIAL — 


CHAPTER 8 (G}— 


UNILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS USING MIXED 
CIPHER ALPHABETS 


Section |_¢€) GENERATION AND USE OF MIXED CIPHER ALPHABETS 


8-1, (Mixed Cipher Alphabets 

a. Mixed cipher alphabets differ from standard 
cipher alphabets in that one or both of the sequences 
is a mixed sequence. A mixed sequence is a series of 
letters that does not correspond to normal sequential 
order of the alphabet used. As a general rule, a 
mixed cipher alphabet will consist of one of the 
following mixes. 

(1) The plain component is a standard sequence; 
cipher component is a mixed sequence. 

(2) The plain component is a mixed sequence; 
the cipher component is a standard sequence. 

(8) Both components are the same mixed 
sequence with displaced points of coincidence. 

(4) Both components are different mixed 
sequences. 

(5) Both components are the same mixed 
sequence but one reversed. 

b. Two main types of mixed alphabetic sequences 
are randomly mixed and systematically mixed 
sequences. The latter type because it is based upon 
a scheme that by its nature is systematic, is useful 
because it makes possible the derivation of one or 
more mixed sequences from easily remembered 
words, phrases, or similar keys. Additionally, it 
does not require written documentation. A dis- 
advantage in producing a mixed sequence through 
a systematic disarrangement is that the possibility 


Example: 


of its analysis is always present. As practical 
considerations set a limit to the complexities that 
can be introduced by systematically mixing an 
alphabet, where greater security is required, ran- 
domly mixed alphabets are used. 

c. Randomly mixed alphabets give more crypto- 
graphic security than do the less complicated 
systematically mixed alphabets because they give 
no clues to the position of letters. Whenever the 
laws of chance operate in the construction of a 
mixed alphabet, a thorough disarrangement is 
likely to be produced. The primary disadvantage 
of random alphabets is that they are not susceptible 
to local generation. They must be reduced to 


‘writing and distributed to all interested corre- 


spondents with explicit instructions pertaining to 
their use. , 


oa ee Mixed Cipher Alphabet 


a. Yne of the simplest types of systematically 
mixed sequences that is. used in a cipher alphabet 
is the keyword mixed alphabet. In this type. the 
disarrangement is achieved through the use of a 
keyword to establish the framework of the sequence. 
The sequence begins with the keyword. Any letter 
repeated in the keyword is used only once, at 
its first appearance. Thereafter it is dropped. These 
letters are then followed by all other unused letters 
of the alphabet in their normal sequence. 


Keyword: CRYPTOGRAPHIC 

Repeated letters dropped: CR YPTOGAHI 

Letters not appearing in keyword added in their normal 
sequence: CRY PTOGAHIBDEFJELMNQSUVWXZ 


b. This type sequence, when paired with a se- 
quence other than a reversal of itself is nonreciprocal. 
When positoned against a double inscription of it- 
self it is nonreciprocal, except at one juxtaposition. 
Therefore, for convenience in enciphering and de- 
ciphering, two alphabets are constructed, an en- 


ciphering alphabet in which the letter of the plain 
component coincides with the normal sequence, and 
au deciphering alphabet in which the sequence of 
letters in the cipher component coincides with the 
normal. 


CONFIDENTIAL a1 


CONFIDENTIAL 


Example: 


— 


Enciphering alphabet 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 
C CRYPTOGAHIBDEFJKLMNQSUVWXZ 


Deciphering alphabet 


C ABCDEFGHIJKLMNOPQRSTUVWXYZ 
P HKALMNGIJOPQRSFDTBUFVWXYCZ 


c. The keyword or phrase used need not consist 
of any definite number of letters, although those 
which most thoroughly disarrange the normal se- 
quence are most appropriate. The reasons for this 
can be seen in the enciphering alphabet above. 
Note that the two distinct segments of the cipher 
sequence are obvious, the keyword and the remain- 
ing alphabetic sequence. Note also that in the de- 
ciphering alphabet, neither is completely apparent 
though there is evidence of sequencing shown 
underlined. The importance of the former charac- 
teristic is that it provides the analyst with a means 
whereby the solution of a cryptogram is hastened. 
The analyst needs only to reconstruct the cipher 
alphabet in terms of an enciphering alphabet, as 
analysis of the message progresses, using each value 
as it is recovered. Once a partial recovery passes a 
certain point, it may be possible to recover the 
alphabet using pattern alone. 


8-3. (Transposition Mixed Cipher Alphabets 


a. It is possible to disarrange the sequence of an 
alphabet even more thoroughly by applying any 
one of the transposition methods treated previously 
as cipher systems. The alphabet to which the trans- 
position process is applied may be either a standard 
alphabet, a keyword mixed alphabet, or even a 
random alphabet. In a random alphabet, little is 
gained by disarranging the sequence. Some of the 
possibilities offered by this method are illustrated 
below: 

(1) Simple columnar transposition using key- 
word mixed alphabet: 


QUADRNGLE 

BCFHIJKMO 

PSTVWXYZ 

QBPUCS AF TDAVRIWNIXGEKEYLMZEO 


(2) Numerically keyed columnar transposition: 
856347261 
UNILTERA 
BCDFGHJK 
MOPQSVWX 
YZ 
AKXEHV I DPLFQNCOZRIWTGSUBMY 


(3) Route transposition (alternate vertical): 


VEHICULAR 
BDFGJKMNO 

PQSTWXWZ 

VBP QDEHF STGICIWXKULMYZNARO 


6. The systems of disarrangement above produce 
certain patterns as a result of the mechanical process 
involved, and due to the alphabet selected for 
disarrangement, which will provide the analyst 
with a means of recovery. Note that the keyword 
appears in the first row and that the succeeding 
rows contain the remaining alphabetic sequence. 
The last row, an incomplete row, contains some 
portion of the sequence UVWXYZ. These last 
letters then are scattered at specific intervals through 
the cipher alphabet by the process of columnar 
extraction. If the extraction is straight columnar, 
the letters appear at an interval equal to the number 
of rows of the matrix, in sequential order left to 
right. If the extraction process is numerically 
keyed, the letters appear in kev number order, again 
at intervals equal to the number of rows. In the 
case of route transposition, patterns also exist but 
they are usually not so pronounced. One such 
pattern is the pairing of the terminal letters. Note 
that WAY and YZ are paired in the alphabet above. 


8-4, (G Decimation Mixed Cipher Alphabets 

a. In this method of deriving a systematically 
mixed sequence, an alphabet, either a normal or a 
keyword mixed sequence, is counted off, letter by 
letter, using a predetermined interval. As each 
letter is decimated, or counted off, it is climinated 
from the basic sequence and set aside. The count 
continues around the alphabet until all letters are 
eliminated. As the letters are eliminated, they are 
set down in the order of their elimination to form a 
new sequence. An example of this method is depicted 
in figure 8-1. 


8-2 CONFIDENTIAL 


~GONFIDENTFIAL 


Basic alphabet (keyword mixed sequence): 
TELGRAPHBCDFIS KMNOQSUVWXYZ 


Decimated at an internal of 6: 
TELGRAPHBCDF Id KMNOQSUVWXYZ 


LASN5EL2SUSOLESNSOLESN5EL2 
x 
she 2158 12345 "61238 6 
q 
123 "y 5612 34561 2345 6 
M y 


H 
123 4 5 61 234 5 6123 
B Ss 
h56 12 3 4561 234 


L K 
56 12 3 45 6 123 
E N 
4 56 1 23 456 
P 
1 2 3° 45 61 
U 
2 3 4h 56 1 
J 
2 3 h 5 6 
V 
1 2 3 4 
5 6 66 1 2 
R 
3 45 
6 1 2 
T 
3.4 
5 6 
I 


AFOXGDQ@ZAMYBSLKENPWUJVRTIC 
As C is not eliminated in the decimation process, it accordingly appears: 


as the last letter of the sequence. 


Figure 8-1 Va Derivation of mized sequence by decimation (U). 


ABCDEFGHIJKLMNOPQRS TUVWXYZ 
12345123451234512345123451 
E J QO. T Y 
23451234512345 - etc. 
D I i 


6. Another method of decimating an alphabet, 
which is at once simpler but also limited, is to use 
each letter in the count whether or not it has been 
used before. For example, in figure 8-2 the standard 
alphabet is decimated at an interval of five. EJ OTYDINSXCHMRWBGLOQVAFKPUZ 


Figure 8-2 (C). Decimation, reuse of letters in count (U). 


CONFIDENTIAL — = 


= 


The limitation of the method is that the interval 
must be an odd number, as even numbers will 
cause repeated letters. For example, in figure 8-3 
a standard alphabet is shown decimated at an 
interval of four. 


ABCDEFGHIJKLMNOPQPSTUVWXYZ 
123412341234123412 34123412 
34123412341234123412341234 
12341234 


DHLPTXBFINRVZDH Repeated letters. 


Figure 8-3 (C). Repetitions in decimation as a result of even 
numbers as interval (U). 


Section Il. RECOVERY OF MIXED CIPHER ALPHABETS 


8-5. (Z) General 

a. Fhe analyst should always attempt the re- 
covery of the method used in generating the cipher 
alphabet. simultaneously with the analysis of the 
cryptogram. This effort is to be distinguished from 
the normal reconstruction of the cipher alphabet 
which occurs as a matter of course with the analysis 
of a cryptogram. The purpose of recovering the 
method of generation of a cipher alphabet is to 
enable the analyst to recover the cipher alphabet 
in its entirety and thereby aid in the solution of the 
eryptogram. If sufficient cipher-to-plain values can 
be obtained by reconstruction as a by-product of 
analysis of the message, the possibility exists that 
they may be used to determine the method of gen- 
erating the cipher alphabet. Where this can be 
achieved early in the solution of the message, a 
great deal of effort can be saved and, in some cases, 
transform the process of cryptanalysis to one of 
decipherment. 

5. Cipher alphabets should be reconstructed in 
the form of enciphering alphabets, the plain com- 
ponent in alphabetic sequence. This is important 


for two reasons. First, if the sequence of the cipher 
component has an observed pattern, decimation. 
keyword, etc., it will appear in this arrangement. 
Thus any evidence of system in its construction. 
however slight, may serve to collaborate identifica- 
tions already made, and may yield the clues necessary 
for complete identification of the method used and 
total recovery of the alphabet. Second. once a 
method of cipher alphabet generation has been 
determined, it affords an insight into the general 
method, keys, and keywords used and may be of 
assistance in subsequent studies of similar messages. 


8-6. Recovery of Keyword Mixed Sequences 

a. Recovery of keyword mixed sequences. when 
used as the cipher component with a standard 
sequence as the plain component, presents little 
or no difficulty. The primary problem likely to be 
encountered is one of recognizing the keyword 
‘given only a few values. However, even here a few 
rules apply that will aid the analyst. For example. 
the partially reconstructed enciphering alphabet 
below was derived through the analysis of a message. 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


C S Z 4 


b. A keyword mixed sequence can be divided 
arbitrarily into two segments, that composed of 
the keyword and that composed of the remaining 
a'phabetic sequence. Having previous knowledge of 
what constitutes the normal alphabet and _ its 
sequence, the analyst can use this with a minimum 
of recovered values to recover the keyword segment, 
the unknown. Examination of the cipher sequence 
above reveals the possible position of the two seg- 
ments divided by the letter Z. It is possible that 7 
is part of the keyword but not very likely. If the 
keyword starts at this point, it runs to some point 
to the right. The cipher sequence DFGT is natural, 
a good alphabetic sequence possibly marking the 
resumption of the alphabetic sequence and therefore 
the end of the keyword, except that the E and H 
are missing. The A is noted preceding the sequence 


TH 


DFGI 


DFGI in the keyword segment. The &. 
frequency letter, is safely assumed to be a part of 
the keyword also. 

(1) The object now is to determine 
letters of the alphabetic segment. By so doing, 
certain letters can be eliminated which must then be 
part of the keyword. The space between the S and 
Z provides for only three letters. In the alphabetic 
sequence, six letters appear. But of the six, 1 and 
T are already placed leaving four letters, CUWAY. 
Also the space between the TH and the /) provides 
two spaces for the letters ABC. Of these possibilities. 
it is far more likely that the placement is C.YY 
and BC, though the former may also be UW.N. 
Accepting the combination UXY, the alphabet is 
now shown as follows: 


a high- 


those 


P ABCDEFGHIJKLMNOPQRS TUVWXYZ 


C SUXYZ V 


THBCDFHI 


8-4 GONFIDENTIAL 


CONFIDENFIAL— 


(2) At this point, the assumed value is checked 
against the cryptogram by attempting further 
decipherment, success confirming the assumptions. 
Further analysis‘ of the sequence depends upon the 
discovery of new values as a result of confirming 
the assumed value, i.c., the whole process is like a 
series of building blocks. The assumption of one 
letter may aid in completing a word in a cryptogram 
or may suggest another letter which in turn provides 


the basis for the assumption of yet another value. 
This value then is checked against both the alphabet 
and the frequency distribution of the ciphertext. 
This in turn enables the analyst to expand the 
cryptogram and the cipher sequence. For exaniple, 
assume that in the process of confirming the letters 
assumed previously, the analyst finds that the 
letters Hp=ae, Lp=0Oc, and Wp=Ke. The alphabet 
how appears: 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


Cc SUXYZL AV 


(3) On this basis, Je is equated to Vp by posi- 
tion alone and so placed in the sequence. The place- 
ment of M, N, P, and Q is now quite easy. Three 
of the four must be associated with X, Y, and Z of 
the plain sequence. Zp, a low-frequency letter, lends 
itself admirably to this association. The analyst 


ORTHBCDFGIJEK 


need only check his distribution for one of the 
letters M, N, P, or Q which cither docs not appear. 
or appears rarely. For example. finding no occur- 
rence of a Qe he at once equates it to Zp. because it 
is the only letter which immediately precedes the s. 


P ABCDEFGHIJKLMNOPQRS TUVWXYZ 


Cc SUXYZL AV 


(4) The letters now remaining to be placed 
are EH, M, N, P, and W, openng two possibilities. 
The keyword is assumed, if evidence warrants. 
Each value is checked by decipherment or by using 
the frequency distribution. The plaintext value is 
assumed and then checked by decipherment. In 
any event, @ solution-is soon reached. 


8-7. Recovery of Transposition Mixed Cipher 
Alphabets 


a. The recovery of transposition mixed cipher 


ORTHBCDFGIJSJEK Q 


alphabets involves essentially the same processes as 
the cryptanalysis of transposition ciphers. Ti the 
latter, the analytic attacks are based upon the in- 
herent characteristics of the system with initially 
little or no knowledge of the plaintext other than 
any characteristics which may have appeared in 
the ciphertext. In the case of transposition mixed 
ciphor alphabets however, the analyst is dealing 
with several known factors. For example, examine 
the enciphering alphabet below. 


P ABCDEFGHIJKLMNOPQRS TUVWXYZ 
C RAMEBPCDQOFVNGWSHXNTIVURKZIL 


(1) The cipher component is not a keyword 
mixed sequence. A keyword may have been used to 
prepare a base alphabet, but on appearance this 
base appears: to have been systematically disar- 
ranged. This could have been done in one of two 
primary ways, transposition or decimation. Assum- 
ing then that the alphabet was produced by some 
means of transposition, the analyst scans the sc- 
quence for some pattern. The V, W, X, Y, and Z 
appear at an interval of 3, suggesting columnar 
transposition. Decimation is not considered, as all 
these letters appear in sequence past the midpoint 
of the cipher sequence. The significance of this will 
be dealt with later. Using the VWXYZ cluster as a 
base, a fragmentary matrix is constructed. 


ONSTU 
FGHJK 
VWXYZ 


(2) The second and third rows show good 
sequential order, while the first suggests a keyword 


fragment. Accepting this keyword fragment, the 
next step is to continue to expand the sequential 
pattern of the second and third rows. Two clusters, 
(PQ and HBP, show a sequential relation in the 
second and third characters and are added. 
ECONS TU 
BDFGHOIK 
PQVWNXY2 
(3) Again the sequence in the second and third 
rows is good. Missing letters, except the J and R, 
already appear in the first row. Both the 7 and &, 
with their associated letters RAL and /Z,. are 
placed using the sequential pattern of their associ- 
ated letters. RAM is placed at the left, as A and AL 
precedes B and P; and /Z is placed to the right as 
the Z follows a K. Note that in the case of the /Z, this 
cluster consists of only two letters, a characteristic 
of the extreme right of an incompletely-filled matrix. 
Thus the matrix now appears fully recovered: 


CONFIDENTIAL —— a5 


RECONSTUI 
ABDFGHJKL 
MPQVWXYZ 


b. Note that this solution differs from the first in 
that a complete cipher sequence is studied, and no 
correlation of its values to a cipher message is 
required. Given a complete sequence, it is always 
easier to recover the system of generating it than 
to work with only fragments of a sequence. How- 
ever in so doing, some of the value of recovery is 
lost, i.e. it does not aid in the analysis of a message. 
The recovery of a cipher sequence from fragments is 
more difficult but far more rewarding in terms of 
actual use 


8-8. (Z) Derivation of a Numeric Key 

a. In those cases where a cipher alphabet is 
generated by keyed columnar transposition, the 
same techniques given above are applicable to the 
recovery of the matrix. The numeric key involved 


1 2 3 4 5 6 7 #8 9 
CDQEBPILNGWOFVRAMSHATIYUKZ 
RAMEBPCDQOFVNGWSHXTJYYUKZIL 

20 ok 5 oe ee UG 


is then determined by noting the order in which the 
columns of the matrix appear in the alphabetic 
sequence. For example, observe the relationship 
between the columns of the matrix in figure 8-4 
and the order of their appearance in the alphabctic 
sequence. 


ie aes a = «SR 


Figure 8-4 vA Relation of column order to sequence order (U). 


6b. When compared to the straight columnar 
sequence, a difference in the location of the UVWXYZ 
cluster is seen as shown in figure 8-5. 


Figure 8-5 P geen? of sequences (U). 


Note that the sequence is now somewhat disturbed, 
but also that the interval between each of the letters 
is still 3. Therefore, by starting the column above 
the base cluster VWXYZ, the same result is obtained. 
The bottom two rows show alphabetic sequence, 
less those letters appearing in the top row as part 
of the keyword. 


8-9. (OS Recovery of Decimated Sequences 

a. The characteristic which provides the basis 
of analysis and recovery of decimated sequences 
is the cyclic permutations of the letters of the 
sequence imparted to them by the decimation 
process. The characteristic is seen in the examples 
below. 


Example: E JOTYDINS XCH 
- - - - H----J- - 
1 2 3 4 12 3 4 1 2 
~--+- D-~ -'- ~ J-- - 
2 3 4 12 3 4 1 2 3 
~ - C ete. 
3 4 


After all the letters of the cipher sequence are 
counted off, the cycles are compressed into one to 


(1) Where a cipher sequence is derived by a 
count where all letters are used, none excluded, a 
constant interval of its multiple occurs between 
the letters that are adjacent in the base alphabet. 
For example, in the alphabet below, note that the 
interval is 5 between the letters E-J, O-T. and 
Y-D. Note also that the interval of 5 is constant 
in reverse, B to A and C to D, indicating that these 
letters were taken out of the alphabet in reverse 
order and after other letters normally preceding 
them. Using the characteristics, the alphabet is 
easily recovered by counting off the letters, thus 
placing them in their original sequence. Spaces 
between the letters are filled by letters in sequence 
as the count is continued. 


MRWBGLQVAFKPUZ 
os ee ae eee 
3.4 12 3 4 12 3 4 l 
BANG Bots cet IS bd ae ee ee, 

4 2 3 4 12 3 4 1 2 


reform the basic alphabet. 


ABCDEFGHIJKLMNOPQRS TUVWXYZ 


8-6 


GONFIDENTIAL 


~ GONFIDENTIAL- 


(2) In the case where the cipher sequence is viously placed, in effect duplicating the generation 
derived by a count which excluded letters once process. For example using the alphabet below, the 
they were used, the same counting system as above count appears: 
is used, but the count does not include letters pre- 

CF I LORUXAEJTJNSWBHPVODOMYKZTGE@Q 
- -@C--+F --T--L--0--R--U--X - - 
123 12 3 12 3 12 3 «212 3 «2123 «31 2 3 «21 2 3 « «21«<2 
A--E-+--J--N--S8S - ~W- - 

812 3 12 3 «1283 «1 2 3«2122 3«21« «2 

B 

3 


The count is continued until the basic alphabet is recovered. 
ABCDEFGHIJKLM™MNOPQRS TUVWXYZ 


b. In both examples above, solution is predicated alphabet is used as the base,. it may be somewhat 
on the ability of the analyst to determine the proper more difficult to determine the correct interval, 
intervals. In both instances, since a direct standard but not an impossibility. Note the characteristics 
alphabet is used, this interval is easily determined, of the two segments of the keyword mixed alphabet 
being found as the distance between adjacent letters in figure 8-6. 


of the base sequence. Where a keyword mixed 


Keyword: ABSTRACTION 


ABSTRCIONIDEFGHY KLHPQUVWKY GZ 


Keyword Segment Alphabetic Sequence Segment 


Figure 8-6 (C). Keyword and alphabetic segments, keyword mized alphabet (U). 


(1) In the sequence above, the normal aipha- the analyst to determine the interval in the deci- 
betic progression still remains, even though it may mation process. If the alphabet above is decimated 
be missing some of its component letters. The at an interval of 4, used letters not recounted, it 
UVWXYZ cluster is unchanged. These two ele- appears as: 


ments, particularly the cluster, provide a basis for 


TOFKQXBIGEMWSODLYCJIJZEVNAURPH 


(2) This sequence contains certain patterns Keyword mixed sequence decimated at an interval 
which are normally different from a decimation of a of 4: 
direct standard alphabet. Taking out the first three 
elements of the two decimated alphabets shown TOFKQX 
underlined, which end with a letter of the VWXYZ 2 - : oe W 


cluster, this pattern can be seen. 


Direct standard sequence decimated at an interval 


of 3: (3) In the first set, the alphabetic progression 


CFI LORUX is constant at an interval of 3 (C--F--/--L 
AEJINSW etc.). In the second set, the alphabet progression is 
BHPV not constant nor is it at the same interval. 


T 0 Ree Et BIE SEG 


468-095 O- 72-7 


The absence of a constant interval between the letters 
and the lack of alphabetic progression within the 
individual elements indicates that the sequence is 
derived from:a mixed alphabet base. 

(4) Since the recovery of the base alphabet 
depends on determining the decimation interval, 
some means must be used to find this. The simplest 


method is through the use of the UVWNXYZ cluster 


letters. Note that in the second decimation process 
illustrated above, the .Y, W, and Y each mark one 
run-through of the alphabet, ie. letters are ex- 


tracted at a given interval, in this case 4. The first 
letter to be extracted is T, then O, then A, then Q, 
then X. Then the process starts again arotnd the 
alphabet. The sequence T to .Y contains six letters. 
Six divides into 26, 4 times with a remainder of 2. . 
Therefore, the interval is 4. 

(5) Tf the assumption of 4 as the interval is 
correct, When applied to a similar cipher sequence 
it produces a keyword mixed alphabet. To illustrate 
the procedure, note the recovery shown in figure 
8-7. 


DBHPXHCKVAEMSOQRVTLZYWIGUE 


5 letters 


264525+1 


interval of 5 assumed 


ler ee Dim SY ie eRe: Shee PNG AS en SP Se ea 


| 


a a as Ei 


oe hie ee Poe ~ me 


ete. 


Figure 8-7 (C). Recovery of a decimated alphabet (U). 


Note that the count above did not include letters 
once placed. If they are included, the sequence 


PS | ea: ee 
Be NP det So. Ss. cin YAS Ss 


appears incorrectly as illustrated below: 


ee: eee a ee ae 
Sok Dicat Shy 


alphabetic order reversed 


The count continued, as in the first example above, results in the following alphabet: 


STANDRIZOBCEFGHIJKLMPQUVWXY 


Keyword: STANDARDIZATION 


Section Ill. (O SOLUTION OF UNILITERAL MONOALPHABETIC MIXED ALPHABET CIPHERS 


8-10. DQ System Identification 


a. The first step of cryptanalysis is the identifica- 
tion of the system to which a given cryptogram or 
series of cryptograms belong. Determination is 
based on certain characteristics imparted to the 
ciphertext by the method of encipherment. In 
the case of uniliteral monoalphabetic substitution, 


identification is usually easy, based on the spatial 
relationship of peaks and troughs of the normal and 
the cipher distributions. Where they canitot be 
matched, the logical assumption is that a mixed 


cipher alphabet is used. For exainple. the frequency 
distribution of the ciphertext of the following 
message appears as: 


AAAAQ QFFQU PKRTT SWZRG QFNWD AERIN WDANW 
DAFAO ADDAK OADGR GZRGI RURGR FMAXU DARE! 
AQVEE WJIWGE RLEWJ WGEFA HMAID DWZRO WGFAKR 
TTEHW QDGWQ VQFFQ UPEFA HVRIR ERAGU AVOQG 
VAXXA IDFCV RJIJRER AGKRT TSWOA JWVXD ANOUD A 
EFEDAQ VEFCD WWNWD AFCDW WFADA QVYIG UFRAG 
WRZCF EWJWG ERLEF AHAGW AGWDW ZRONG FREVER 
JRERA GDWEW DIWXY AAAAQ 


(1) Note that in compiling the frequency 
distribution, the first and last groups of the text 


are not used, as they are system indicators. 


ae CONFIDENTIAL 


: 


THAT THH TAT THY 
9 Illl 

THA HHH 

{fll 


TTA TH II 
ll 


SHH Ill 
>» (til 
a 


= TH 
SO THI 


=| 
ry || 


Do TH THUAN A 
== HAT HHA 
De HHL 

| 


© THI 
t || 
HH | 
SHI 
— Hl 
ws TH 


300.8 22.21.1899 35 94 38.25 8 2 it 2626 7 0 30-6 15 


Figure 8-8 (U). Uniliteral frequency distribution, mized monoalphabetic substitution (U). 


(2) The pronounced peaks and troughs of the 
distribution shown in figure 8-8 are characteristic 
of uniliteral monoalphabetic substitution. If it is 
nonmonoalphabetic, it appears flattened. Further, 
the difference in spatial relationship of the peaks and 
troughs between this distribution and a normal 
distribution indicates that a mixed cipher sequence 
is used. 

b. In this particular example, visual examination 
suffices to show that the system in use is probably 
monoalphabetic and uniliteral. This is caused by 
repeated occurrences of plaintext values which are 
duplicated in the ciphertext, only in different terms 
and easily revealed by the frequency distribution. 
This phenomenon is not always so evident. When 
such ev dence is not at hand, the analyst must use 
other statistical tools to aid in the identification of 
a system. Moreover, the analyst may use these 
tools to further substantiate his identification made 
by visual inspection. 


8-11. (QZ) Statistical Identification 

a. SeVeral statistical tests are available for the 
identification of a system where the uniliteral fre- 
quency distribution does not reveal significant char- 
acteristics, either because of the shortness of the 
message, or because of the lack of internal charac- 
teristics in the plaintext. For short messages, in 
particular less than 200 letters, the expected fre- 
quency table will aid in the classification of a cryp- 
togram as either substitution or transposition, and 
the Lambda (A) or blank expectation test provides 
a means of identifying a substitution system as 
either monoalphabetic or nonmonoalphabetic. These 
tests given as tables are contained in paragraph 
2-12 and their use explained in detail. 

6. In addition to the tests above, the Phi (9) 
test is also used to determine whether a given cipher 
is monoalphabetic or nonmonoalphabetic. The Phi 
test is a test of the observed occurrence of a given 
letter as contrasted to its expected random occur- 
rence and its expected plaintext, or normal occur- 
rence. The details of operation of the test are 
contained in paragraph 2-15. 


c. An alternate way of testing whether a crypto- 
gram is monoalphabetic is by determining the Phi 
Index of Coincidence (¢@ I.C.). The ¢ I.C. is the 
ratio of the number of observed occurrences (go) to 
the number of expected random occurrences (or). 
Shown in formula the ¢ I.C. appears as: 


’ tee” 
or 
Actually this method used the same values as the 
Phi text, only expressing their relationships some- 
what differently. That is, the @ I.C. gives, in terms 
of a ratio, the nearness of go to ¢r. For example, 
the values given in paragraph 2-15 for go, ¢r. and 
op are: 
Observed occurrence go0=154 
Expected random gr= 94 
Expected plain op= 164 


In terms of the @ I.C. the ratio of ¢o to ¢gp is: 


154 
1.C.=—— = 1.64 
: 94 


The greater the value of the @ LC. the stronger the 
indications of monoalphabeticity are. To illustrate 
this, consider the case where go and ¢r are equal: 


pO a POS At Gb 
op= 100 100 
d. The theoretical @ LC. of English plaintext is 
.0667 
.0385 
0385 
.0385 
by the fact that .03885 and .0667 are respectively 
the random constant and the plain constant of 
English in decimal terms. As uniliteral monoalpha- 
betic substitution does not change the relative value 
of occurrence of letters of the plaintext but only 
their alphabetic identification, the ¢ I.-C. can be used 
for determining the monoalphabetic or nonmono- 
alphabetic nature of the system. Thus, the @ LC. 


equaling 1.73, and the LC. of random text Is 


equaling 1.00. These values are determined 


CONFIDEN FAL — 8-9 


of the cryptogram being examined, 1.64, can be 
compared to the @ I.C. of plaintext, 1.73, and random, 
1.00. As it approximates the ¢ LC. of English plain- 
text, the system is assumed to be monoalphabetic. 
If the @ I.C. of a cryptogram closely approaches the 
¢@ I.C. of random text, we assume that the system is 
nonmonoalphabetic. The degree of approach is a 
a matter of the cryptanalyst’s judgment. 


8-12. (CJ Preparation for Analysis 

a. As a preliminary step to analysis of any 
cryptogram, the analyst should organize his work. 
Given a cryptogram to analyze, a work sheet is 
prepared. This need not be elaborate, but is in a 
format that lends itself to study and one which can 
be kept and used as a record of the solution, the 
actual work being performed on similar sheets. 
-Also as an adjunct to the work sheet, the analyst 
keeps a technical summary of the solution explaining 
in some detail the steps followed and their success 
in obtaining a final solution. This is especially 


12345678 
A QFFQUPKRTIT 
B AERLNWDAWN W 
C OADGRGZPRG J 
D DAEEDAQVE E 
E WGEFAHHAT D 
F TTEHKHWQDGW Q 
G HVRIJRERAG U 
HE IDFCVRAIRE R 
I JWVxdDAOUD A 
J WWWWDAFCD W 
K UPFPRAGWRZC FPF 
L AHAGWAGWD W 
M JRERAGODWE W 


ONHEemMrnanxso Van 


important in the case of solutions of new systems, 
and in those instances where another analyst is 
expected to use the result produced. Although there 
is no specific format for either the example given 
below and those in following paragraphs, they serve 
as models, — 

b. The ecryptogram for analysis is copied on a 
work sheet of 14-inch cross-section paper. If copied 
by hand, the writing is in ink and each letter is in 
accordance with the standard military printing 
system. In the case of monoalphabetic unilitera| 
ciphers, the message is copied as individual letters, 
regardless of the groupings of the message text, one 
letter to a cell with a space between each. To aid 
in the references to a particular letter, row and 
column coordinates may be assigned. Horizontal 
lines may be identified by capital letters and vertical 
rows by numbers. Thus, Al equates to the first 
letter of the cryptogram, row A, column 1. This 
format is shown in figure 8-9. 


9 10 11 12 13 14 15 16 17 18 19 20 


GVamemyynoozTtriyuases 
ZHOVSBONOMNED AN 
RSETORDOWVDRHAARD 
KOAABORWHAOOHADOON 
aAmODYQI CTP Dyno 
wus HE WOM SO 
Hoe PSN Sy oe oS 
SHH QO YR EPR 
Ww 'YeQOonBB Ba UV cro 


Figure 8-9 A Ciphertext work sheet (U). 


ce. After the work sheet is prepared, the text is 
closely examined for repetitions within the text. 
Such repetitions, a characteristic of monoalphabetic 
substitution, are indications of identical words or 
expressions in the underlying plaintext and prove 
to be extremely useful in the assumption of letters 
and whole words. The search normally begins for 
' digraphic and trigraphic repetitions, these being 


8-10 


easiest to locate. They are further examined for 
possible extension of repetitions of greater length. 
In the search, note any reversible repetitions. As 
the repetitions are found, underscore them indicating 
the direction of progression of reversible digraphs 
by an arrowhead. Properly marked, the work sheet 
appears as in figure 8-10. 


CONFIDENTIAL 


~ CONFIDENTIAL 


12.3% 926.7 89:20:11 12 33 Th 15-16-17 18 19 20 
A Q@FFQUPKRT 2 SWZRGEQF NWO 
B AERLNWDAi W DA*PF AOA DOD AK 
C OADGRGZRG J RU RGR PF HW AX U 
D DAFEDAQVE EWesdwWiGERLE Wd 
E WGEFAHMNAI D DW ZR OW GE KR 
F TTEHWQDGW@V¥QFF@QUPEPFA 
GC PVRTRERAG UA 0-0 OC VA Xk XA 
H IDFCVRJRE FR AGKRPPSWOA 
I JWVXDAOUD A EE DAQVE FC D 
JI WWHWDAFCD WWPAODAQVYd2£IG 
K UFRAGWRZC FEW dW GE ROLE PF 
L AHAGWAGWD W ZR OW G FPF RE VR 
M JRERAGDWE WDIWk Y 


Figure 8-10 ( 


8-1 2 (27 Bir and Triliteral Frequency Dis- 
tribuiion 


- a. In order to study and make use of the repeated 
patterns underscored, a frequency distribution of 
digraphs and trigraphs may be made. Properly 
compiled, this data provides a base for comparison 
of repeats in the ciphertext against similar digraphs 
and trigraphs which occur in English plaintext, 
and which also aids in the identification of vowels 
and consonants. Basically there are three methods 
of compiling this data. 

(1) Each letter of the ciphertext may be shown 
with its two preceding letters, a triliteral distribution 
with two prefixes. 

(2) Each letter may be shown with its two 
succeeding letters, a triliteral distribution with 
tivo suffixes. 


. Ciphertezt prepared for analysis (U). 


(3) Each letter may be shown with its preceding 
and succeeding letters, a triliteral distribuiion with 
one prefix and one suffix. 

b. For the study of monoalphabetie ciphers, the 
last method is most satisfactory and will be used 
here. In its construction, it is quite simple. Across 
the bottom of a sheet of cross section paper, a cipher 
alphabet is inserjbed in its normal order. Above 
each letter, arranged in columns, the letters which 
precede ahd succeed it in the ciphertext are entered. 
The paired letters then represent the prefix and 
suffix, in that order, of the letter they are inscribed 
above. Below the horizontal alphabet in parentheses 
is the frequency value of that letter, the same values 
that appear in the uniliteral frequency distribution. 
An example of this method of constructing a tri- 
literal frequency distribution using the ciphertext 
is shown in figure 8-11. 


8-11 


CONFIDENTIAL. 


(30) (0) (4) (22) (21) (18) (13) (4) (3) (9) (4) 


(3) (2) (5) (8) (2) (11) (26) (2) (6) (7) (9) (36) (6) (1) 8) 


A PB ¢C OD E F G H I J K L M N O P @ R S 7 Uv YoeoW BOYS eg 
OE FV WA AR QF AQ AM AD GR PR RE FA FW AA UK -F AT TW RT QP GE Sz AU VI WR 
WA AN FU ZG WD 
Dis FD WA AE FQ DR EW AD WW AQ RE HA LW KA UE GF EL TW TS RR @@ lb Ax uP 

DF Qi AW HR AV 

FO FD AD ED AA RZ AV YG WW FR WW RW AY RT 4b GA ND XA We 
GG id 

OD 2F DA VE Ril RJ AA. RR GR OG AO WD ZG TE QP CR dG Vo ae 

DK GD 

OD AG EW EA A&R RR OG WV dU AT GA WX kJ wy We 
UG OG 

HX UA GR GK WE AW WA VF GF TS OD GE JG Xa 

DE EA IW QF WE WW AU FU EL GF GY Dz 

DQ ID GF FQ WF RR RN OG Zz f OG 

FH DW TH EA DW DW AV kT HQ 

MI QG PF DC AU AV Ve GQ 

FH IF RR &C QV Jk SO 

RG XA RR AC AK EA JV 

uo UA AE WA IU VE DW 

VX EA ED UR AW JE Wit 

xI CH VF CE WE EA ND 

RG WA FW EA AW KT DW 

Of CW GR GR AW FA WE 

DO AA LG WZ AV 

DE WW ORV WF EL G. 

De GW  =RR AD 20 id 

OF, WI WW FE JG 

FD Ves GA 

DQ dE GD 

RG A Lc 

FH oE 

dG OG 

WG iD 

RG Jk 


c. The method used in figure 8-11 constructing 
the triliteral frequency distribution provides a com- 
plete list of all trigraphs and all digraphs in the 
cryptogram. Using the table, repeated trigraphs and 
digraphs can be quickly isolated. In studying the 
digraphs, it is immaterial whether prefix and base 
letter, or base letter and suffix, is used, as long as the 
same pair ‘s used consistently. For example, the 
digraphs Di, R.A, and Ft are found using prefix and 
base letter .1; the same digraph can be found when 
base letter D, 2, and F are combined with their 
suffixes. 

d. From the triliteral frequency distribution, 
figure 8-11, the analyst can extract a listing of those 
elements most frequently repeated in order to develop 
a condensed table of repetitions. This table should 


8-12 


Figure 8-11 rie frequency distribution (U). 


also include word-length repeats found in the initial 
examination of the text. The purpose of making a 
condensed table of repetitions is to limit the study 
to those items of the greatest probable importance. 
Therefore in this table, as an arbitrary rule for 
messages of average length, digraphs aud trigraphs 
which occur less than four and three times respec- 
tively need not be listed. At the option of the analyst. 
digraphs of repeated letters, regardless of number of 
repetitions, may be listed. Following each item listed. 
the frequency of its occurrence should also be 
included. Figure 8-12 following, is an example of a 
condensed table of repetitions drawn from the tri- 
literal frequency distribution above and the message 
text. 


DIGRAPHS non 
DA=11 WD-6 RE=4 EF=4 AG=6 
FA=5 EE=3 FF~2 WG=5 
RA-4 
00-1 AQ=3 uR-6 TT'=3 DW=5 
ZR=4 JWea5 
LW-k 
Wau 
GW=4 
TRIGRAPHS 
RAG-4 WDA=4 RER=3 RIT=3 WIW=3 
FAH=3 ERA=3 ERL=3 AGW=3 VWD=4 
DAQ-3 JRE-3 KPT =3 WGE=3 EWI =3 
DAE=3 VRI=3 EFA=3 RIR=3 AQV=3 
POLYGRAPHS 
VRIREPAG=~3 QFFQUP=2 WWUA=4 
WIWGE=3 DAQV=3 


Figure 12 fh Condensed table of repetitions (U). 


8-14, (2F Analysis of Vowel-Consonant Rela- 
tionship 
a. By applying certain known characteristics to 


Of the remaining nine digraphs, five contain an N. 
four contain a T, four are a consonant combination, 
and none are combinations of vowels. , 


the elements previously isolated, it is possible to AN ST 
classify the high-frequency cipher letters into two IN TH 
groups, probable consonants and probable vowels. ON TO 
This classification in turn permits the assumption ND OR 
of plaintext values for those elements, values which NT 


then can be substituted for ciphertext in the cryp- 
togram. The basis for this classification is quite 
simple. The manner in which vowels and consonants 
combine with each other and among themselves is 
different in each case, and they combine with 
characteristic frequency. An example of these char- 
acteristic frequencies is seen in the tables of di- 
graphic frequencies in appendix A. Examination 
shows that the 18 digraphs representing 25 percent 
of all digraphs are composed of the letters: 


ETNROAISDHV 


With the exception of the H and the V, the normal 
high-frequency vowels and consonants will account 
for approximately two-thirds of the eryptogram 
above although they represent only a little more 
than one-third of the alphabet. 


§b. Further examination reveals that of the 18 . 


digraphs, 9 contain an E, three of which are reversed. 


‘"ED EN ER ES 
NE RE SE .-TE VE 


Of the vowels, E combines most readily, and then 
with the N, R, 3, T, D, and V in that order. N 
combines most readily with the vowels, specifically 
with E, O, I, and A, in that order. The consonant 
T combines most readily with other consonants, 
the N, H, and 8, in that order. Therefore, if several 
high-frequency cipher letters are observed combin- 
ing with one letter, the assumed value of Ep, they 
may be assumed to be the equivalents of N, R, 3, 
and T. D and V would be low-frequency combina- 
tions. Those cipher letters assumed to be consonants 
should be observed in combination with another 
group of high-frequency cipher letters representing 
the vowels, A, I, and O. Generally vowel combina- 
tions are limited and should not be observed in 
combination with any great frequency. But certain 
diphthongs may appear in the text, and since the 
digraphs are drawn from the ciphertext in sequential 
order, any one may represent a word bridge thereby 
forming a vowel combination. For example, the 


~CONFIBDENTIAL— £13 


CONFIDENTIAL 


following phrase enciphered, results in_an EO 
combination: 


SHIFT FIRE ON SCHEDULE 
EO Digraph 


c. To apply the foregoing principles, the analyst 
will use the uniliteral frequency distribution, the 
triliteral frequency distribution, and the condensed 
table of repetitions. Only after all the high-frequency 
cipher letters and combinations contained therein 
are studied will any deduced values be applied to the 
cryptogram. The first step then is to list the high- 
frequency cipher letters of the cryptogram using the 
uniliteral frequency distribution previously prepared. 


Prefix: z 
z= = 
Ae ABCDEFG 
a 
Suffix: 
Prefix: ae 
4 =_ Z 
We ABCDEFGHId 
a = 
Suffix: 


QdSV 
1 9 9 
1 


By their frequency of occurrence, the cipher letters 
probably represent the plaintext letters: 


ETN RO AIS DG 


On the basis of frequency, both .1¢ and We are 
equally good choices for Ep. By using the triliteral 
frequency distribution, the combinations of these 
letters can be written out for consideration, using the 
following format depicted in figure 8-13 which shows 
both combinations and frequencies. 


Figure 8-13 (C). Vowel consonant relationships (U). 


Of the two sets of combinations, that of We with 
De, Ec, Ge, and Je seems more suggestive of Ep 
combining with Np, Rp, Sp, and Tp to form the 
reversible digraphs noted in preceding paragraphs 
than does the possible combinations exhibited by . tc. 
For this reason, the choice of We as Ep is assumed. 
If in the course of further study this assumption 
proves incorrect, the -Lc value will be assumed to be 
Ep and the data studied in that light. 

d. If We is Ep, it follows that De, Ec, Ge, and Je 


Vowels 
cipher 
assumed plain (E) 


represent consonants. And, if this is correct, they 
should be found in combination with other high- 
frequency letters which represent the vowels A. I. O. 
and U. Using the condensed table of repetitions, 
these letters are seen as combining readily with .le 
and Fe and less readily with the cipher letters Ve. 
Fe, and Oc. The cipher letters .{ and R probably 
represent the cipher equivalents for two of the plain- 
text vowels A, I, O, and U. The letters Ne, Fe. and 
Qc probably represent consonants. 


Consonants Possible Consonants 
WAR DEGJ 


NFQ 


(1) Further identification of vowels can be made on the basis of the occurrence of dipthongs. The table 
of digraphs shows that the most frequently used dipthongs are: 


dipthongs: IO OU EA EI AI 


Referring to figure 8-12, the digraph RAc appears 
quite frequently. Ace and He being assumed vowels, 
the RA combination should represent a diphthong, 
and by frequency of occurrence the diphthong IO 
is suggested. The frequencies of the individual 
letters, Re and Ac are such that they correspond to 


8-14 


IE AU EO 
frequency: 41 37 385 27 17 18 


AY UE 
13 12 12 ll 


the expected frequency of Ip and Op. Thus the 
plaintext values of I and O are assigned to Re and 
Ac respectively. 

(2) Returning to the suspect consonants. it is 
noted that the cipher letters D, BE, G, and J combine 
well with the assumed Ep (We) suggesting that they 


GONFIDENTHAL 


GONFIDENFIAL—— 


represent four of the plain consonants N, R, S, T, 
and V. The frequency of combination of those 
letters is as follows: 


RE (98) ER (87) 
TE (7) ET (37) 
NE (57) EN (111) 
VE (57) EV (20) 
SE (49) ES (54) 


Study of prior tabulations reveals that We (Ep) 
combines with D, EH, G, and J cipher as shown in 
figure 8-14. 


Prefix: 


We (Ep) 


Hiss TH 
lle {{h 

{HS ti 

JHIS H 


Suffix: 


Figure 8-14 (C). Analysis of Weas Ep (U). 


De, as the most frequent combination with We, is 
accepted tentatively as Rp. The He combination is 
noncommittal but the Ge also shows a good reversal 
pattern, similar to the NE-EN reversal. Further, 
the trigraph RAG is noted on the condensed table 
of repetitions as being of relatively high frequency. 
By previously assumed values, this trigraph equates 
to ION if Gc=Np. Referring to figure 8-12, the 
RAG is seen as a word ending occurring three times, 
each time preceded by He. The plaintext trigraph 
ION is one of the most common trigraphs and is 
usually preceded by T or S, the T being more com- 
mon. Thus Ee likely represents either T or S plain- 


Ec = Sp and Fe = Tp 


text. The preceding table of combinations shows 
that the value of combinations of E with S and T 
are almost equal. Both are equally good doublets, 
ic. TT or SS. Therefore, since the evidence is 
inconclusive for the moment, the Ee is not considered 
further. 

e. The cipher letter F is the next to be examined. 
In the condensed table it is observed as appearing 
in combination with Ee, either Sp or Tp as E’Fc, and 
in combination with itself as a doublet F¥Fe. Al- 
though the F has a high frequency (18) the latter 
appearance casts doubt on its being a vowel. Vowels 
as doublets have the following frequencies: 


AA 3 
EE 42 
sa - 
0O 6 
UU - 
YY - 


The assumed cipher values for Ap and Ep exclude 
two possibilities, and the expected frequency of the 
OO doublet is so low that it would hardiv fit the 
number of occurrences of the doublet F’Fe. Therefore 
Fe is assumed to be a consonant. The high-frequency 
consonants appear as doublets with a frequency of: 


TT 19 S819 -VV0O 

NN 8 DDs8 

RR 11 HH 0 
Considering the foregoing frequencies. it is obvious 
that Fe can also equal Sp or Tp, giving rise to several 
possible coinbinations with Ee, which also can be 
either Sp or Tp. 


Ec = Tp and Fe = Sp 


thus EFe = STp = orthus EFe = TSp 
FFe = TTp FFe = SSp 
HEc = SSp Eke = TTp 


Faced with this choice where the frequency of 
occurrence within the cryptogram is equal, one 
other possibility is open for use in identifying the 
correct plain-to-cipher equation. This is done bv 
checking the relative plaintext occurrences of the 
digraphs ST and TS. The digraphie frequency 
table figure 8-1, shows that TS has a frequency 


P ABCDEFGHIdJKLM 
C Ww R 


The analyst could, using the same techniques 
described, continue the identification of single letters 
by combining the recovered values of cipher letters 
with unrecovered cipher letters, playing the resultant 
frequency of the digraphs against those listed in 
the appropriate frequency tables. However, there 


N 


Q 


value of 19 while the value of ST is 63. Therefore, 
the first combination above, where EFe = STp. and 
where Ee = Sp and Fe = Tp may be accepted. 


8-15. (G) Analysis of Word Pattern 


a. Tofthis point the following values have been 
ussumed : 


OPQRSTUVWXYZ 
A DEF 


is another method of establishing the identification 
of individual letters. This is through -the use of 
word patterns and the probable word method. 

b. In foregoing paragraphs, stereotypes in military 
communications are mentioned. These are certain 
words, phrases, and abbreviations occurring with 


-GONFIDENTIAL 8-15 


regularity. Not only do certain words appear with 
a greater frequency than others, but also certain 
words exhibit specific characteristics of pattern and 
letter usage which are useful to the analyst. Consider 
the following words: 


OCCUPY BATTALION 
LOSSES COMMANDING 


Each is composed of certain letters which occur in 


DEFENSE > 


patterned regularity, certain letters being repeated. 
This phenomenon, called idiomorphism, provides a 
means whereby certain words are readily identified 
and their plain letter valttes assumed. As a means of 
deciphering idiomorphic patterns and classifying 
them, a literal symbol is assigned to the first letter 


-of a distinctive pattern and to each succeeding 


different letter. For example, the words above are 
classified as: 


AA ABBA AABA 
O CC UPY B ATTA LION LO SSES 
ABACDA AABCDEC 


D EFENSE 


Note that the letters A, B, C, D, E, etc. are assigned 
beginning with the first repeated letter of the word. 
Each. time the word letter is repeated, the same 
pattern letter is also repeated. As can be observed 
in the foregoing examples, patterns span repeated 
letters in the word. 

c. The same system of classification is applied to 
cipher repeats that occur in monoalphabetic sub- 
stitution. For example, the polygraphs contained 
in the condensed table of repetitions are classified 
into the following idiomorphic classes: 


~ ABACA ABBA ABCD 
V RIJRER AS QFFQ UP NWD «A 
ABA ABCD 
WJIWGE DAQU 


There are two general ways that these word patterns 
are used: 

(1) In those cases where no cipher-to-plain 
values have been recovered, the analyst assumes 


CO MMANDIN G 


that a specific pattern is a given word. This process 
is in reality only a form of guessing, the correctuess 
of the guess being directly related to the analvst’s 
familarity with the general circumstances surround- 
ing the message and the general nature of its con- 
tents. The use of this method may or may not be 
helpful. Where a word is assumed, values cun be 
assumed which can be applied to other probable 
words, each in turn generating new values. [In some 
cases however, this method involves more time and 
effort than a straightforward analytic approact:. 

(2) The second case involves the use of this 
method in conjunction with other normal analytic 
approaches. Specifically, the values derived from a 
study of vowel-consonant relationships are applied, 
in most cases, to word patterns thus providing a 
firmer base for the assumption of probable words. 
For example, the cipher polygraphs preceding are 
reduced to partial plaintext as follows: 


Idiomorphic class: ABACA ABBA 
Cipher: Voda ET eG QFFQUP 
Plaintext: — {—IsI ON —TT— — 


(3) The analyst, by referring to the listing of 
idiomorphic word patterns in appendix D-3, can 
search the appropriate class for words which contain 
the correct plaintext elements. In doing this, remem- 
ber that the elements dealt with here are word 
patterns and not lengths. The pattern derived from 
an examination of the ciphertext may represent either 
a complete word, a word fragment, or even parts of 
two adjacent words used in the plaintext. Scanning 
the word list of idiomorphic pattern ABACA, only 
one word is found within this class that contains the 
correct plaintext values. 


C VRIRER—AG 
P  -I-ISION 
DIVISION 


In the case of the idiomorphie pattern ABBA, 
several possible words which conform to the require- 
ments are found. 

C QFFQUP 

P TT 


ATTACH 
ATTACK 


Although each word is different, they both contain 
the repeated A. Therefore Qe can be equated to Ap. 


ae CONFIDENFHAL— 


CONFIDENTIAL— 


d. By transferring the new plaintext values with 
their associated cipher values, the enciphering 


P AB 
Cc @Q VW 


At this point, the analyst may choose one of four 
possible routes toward a final solution, or may use 
any combination of these routes. 

(1) Continue a study of word patterns. 

(2) Revert to a study of digraphs. 

(3) Attempt to reconstruct the alphabet above 
using its obvious sequences to assume letter values 
and then checking them by (1) and (2) above. 

(4) Begin substituting the plaintext values now 
recovered for the appropriate ciphertext values in 
the message and then attempting to find additional 
values by reading out valid plaintext. 


R 


C ABCDEPF 


P oO RSTN Vv 
| 5 ae a ie a es 
A QFFQUPKRT T 
Aa? TA I 
B AERLNWDAN W 
Oost ERO E 
COA DERE CAC 
ORNIN INV 
D DAEEDAQVE F 
ROSSROADS § 
E WGEFAHWATI D 
ENSTO ) R 
F TTEHWQ@DGW Q 
S EAR EA 
G HVRIJRERAG U 
DIVISION 
H IDECVRIRE R 
Roe Vo eS 
I JFWVXDAOUD A 
VED RO R O 
J WWNYWDAFCD W 
EE EROT RE 
K UFRAGWRZC F 
TIONETI 53 
L AHAGWAGWOD W 
O ONEONER E 
M JRERAGDWE W 
VISIONRES £E 


CDEFGHIJIKLMN 
G 


G10 I 1241324: 35 


Ss 


NNW ENROoODPoroswDWowyanHtawy 


wo 


sequence is now expanded to: 


OPQRSTUVWXYZ 
A DEF J 


8-16. (C) Substituting Deduced Values 


a. Thus far the values accepted as being correct 
are almost purely hypothetical. They have been 
tested against one another in combinations divorced 
from their context in the message. No matter how 
valid any of the values may seem to be, the final test 
of their validity lies in their consistent application to 
the ciphertext to produce intelligible plaintext. As 
an aid, the analyst may rearrange the cipher-to- 
plaintext relationship to produce a deciphering 
alphabet to decipher the message. This, and the 
partially recovered plaintext is shown in figure 8-15. 


GHIJKLMNOPQRSTUVWKYZ 


Al DE 


16 17 18 19 20 


W ZR G @ F N W D 
E IN A T E OR 
A F A @ A DOD A K 
Oo T O O R R OQ 
U R GR F & A K OU 
IN I T fe) 
J WG E RF LEW ad 
VEN S I S E Vv 
W 2 R OW G F K RF 
E I Bom TD L 
Q F F @ U PE F A 
Ao TP oD hk Ss T O 
O00 8@ G VAX K A 
A N D O 0) 
GLRT?TS WO A 
WN I 
EDA Q V E F €C D 
5S R OQ AD § T R 
F ADA Q VY ¥ IG 
T O R O A D NV 
Wd WGE RL EF F 
EV EW S I 5 T 
R O W G F R E VR 
I EWN T IS DI 
J W x Y 
VE 


Figure 8-16 (C). Partially recovered plaintext (U). 


8-17 


b. Examination of the partially recovered plain- 
text now reveals several sequences which, although 


simple. These newly assumed letters may then be 
substituted for other cipher letters. For example, 


incomplete, contain a sufficient number of key letters 
to make the identification of the others relatively 


the sequence Al through C17 probably reads: 


“ATTACK WILL BEGIN AT ZERO SIX ZERO ZERO 


TOMORROW MORNING” 


From this sequence the cipher-te-plain value can be drawn: 


C UPKTSZNE-0 
P CKWLBGZEXM 


The deciphering alphabet now appears as: 


C ABCDEFGHISJKLMNOPQRS TUVWXYZ 


PO RS TNP wx 


ZMKAIBLC E G 


Using the alphabet for further decipherment, again assuming letters, the message can be deciphered to read: 


“ATTACK WILL BEGIN AT ZERO SIX ZERO ZERO TOMORROW 
MORNING IN VICINITY OF CROSSROADS SEVEN SIX 

SEVEN STOP YOUR REGIMENT WILL SPEARHEAD ATTACK 
STOP DIVISION COMMAND OF FOURTH DIVISION 

WILL BE MOVED FROM CROSSROADS THREE ZERO THREE 
TO ROAD JUNCTION EIGHT SEVEN SIX STOP ONE ONE 


REGIMENT IS DIVISION RESERVE” 
The cipher alphabet used is: 


C ABCDEFGHIJSJKLMNOPQERES 
P OQHRS TNPUVWXKYZMKAIB 


By rearranging the values of the two sequences, the enciphering alphabet can be derived and the keyword found. 


P ABCDEFGHIdJKLUMNOPQRS 
C Q@SUVWXZCR YPTOGAHBODE 


Keyword: CRYPTOGRAPHY 
Hp = Cc 


c. The example presented in the preceding para- 
graphs, being an artificial illustration set up to 
demonstrate general principles, is relatively easy to 
solve. This is so because the frequencies of the various 
elements analyzed: letters, digraphs, trigraphs, and 
word patterns, correspond well with that expected. 
This is not always the case. The principles illustrated 
are general in nature and application, and depend 
upon the formulation of assumptions. Recognize that 
any assumption may be incorrect as well as correct, 
the best means of determination being to test each, 
casting out those that prove incorrect. The analyst 
will find it most profitable to vary the analytic 
approach thus providing a source of additional 
assumptions. In some cases, a single approach may 
suffice to solve a simple cryptogram, but in the long 
run, the more varied the techniques employed the 
surer the solution. 


8-17. (Z) The Consonant Line Method 


a. Another method for the determination of vowel 
and consonant equivalents, which is extremely useful 
in difficult cases of monoalphabetie substitution. is 
the consonant line method. This method makes use 
of the positions of letters in the ciphertext relative to 
the occurrence of adjacent letters and is based tpon 
the tendency for low-frequency consonants to be 


flanked on one or both sides by vowels. If a distribu- 
tion is made of the contacts of the low-frequeney 
ciphertext letters of a monoalphabetic cryptogram., 
vowel-equivalents can be distinguished from conso- 
nants in that they are usually represented by a 


combination of the following characteristics: 

(1) They are usually high-frequency letters. 

(2) They have a variety of contacts. 

(3) They combine readily with low-frequency 
letters. 


8-18 CONFIDENTIAL 


(4) They do not combine readily with one struction of a consonant line diagram, an enlarged T. 
another and less so with themselves. For example, construct a triliteral frequency distri- 
b. The identification of possible vowels using the bution, see figure 8-16. 


foregoing characteristics is simplified by the con- 
A B C DE F GH Ids K £L MN OP QR S TU VW K Y G@ 


US SZ -Y QY ZU QP UQ ZR QD QR KV QS 2X EU CE ZY HC NS QE QX EZ YH 
DQ LQ SE VZ PQ JQ SE SN EQ AQ IH XC YS ED RW RJ UQ QH XQ ER DQ 


ZD ES ER JQ EZ QF US SY DP HZ PE xP SJ QF IX ZR TE RT 
DC SR VS WR HZ JH AR JW KJ RS AU SJ JX WS FR IK 
ZD WY WP QE RH UI TQ EI YS QU RS QF JF SU PZ YX 
DX JQ FQ SI QE RE HJ XT RK SK HQ SD QY xz ITH 
SE YI ZR QS RQ . HS HI VP Qs DZ FS FD 
WE JQ IQ. SY _ IW Ms XX KZ ZR JS YD 
YI RE ZW EF XE EH GR KX 
JQ SV VR VH XY YJ SP YI 
HS QE SJ HV EU YD WZ AE 
RL QE QW C4 PQ UU RU HQ 
DR JS JX FH KX tile Ux 
ry IQ JX UV Si 
ZF OX FX 
HS RI IH 
HQ zZ EJ 
D- PY JW 
NI 
Ed 
FH 
VH 
Figure 8-16 . Triliteral frequency distribution (U). 
Using the triliteral distribution of figure 8-16, a the left. Below the crossbar. the letters used as 
consonant line diagram is constructed as in figure prefixes are inscribed to the left of the vertical part. 
8-17. Above the crossbar, all low-frequency letters under the letters they precede. Those letters used as 
of the distribution (C, K, L, M, N, P, T, V, F, W) suffixes are inscribed to the right, under the letter 
are inscribed horizontally, repeated on the right and they follow. 


CONFIDENTIAL 8-19 


CONFIDENTIAL —— 


CONSONANT LINE 


MNPTVEW 


Figure 8-17 fs . Consonant line diagram (U). 


c. Considering both the number of contacts and 
their variety shown in the diagram, it is likely that 
the cipher letters Q, S, and R are vowel equivalents. 
The cipher letters X, Z, and E also appear possible 
as does Y. However, they represent a total of seven 
letters where there are only six vowels. The normal 
frequency of Up and Yp is less than the high- 
frequency consonants. Therefore, the last four cipher 
letters probably contain one or more consonant 
. equivalents. Having isolated three vowel equivalents 
with some certainty and four other letters as probably 
representing several vowel equivalents, the analyst 
has several options. 

(1) With the most likely vowel equivalents, 


Qo AWCDER¢GHIZK 
Se ABTDEFGHTIE 


the procedures given in the study of vowel-consonant 
relationship may be followed to determine the 
identity of each vowel and associated high-frequency 
consonants. 

(2) A study of each vowel’s contacts can be 
made in order to classify additional consonant 
equivalents. For this, a vowel line is constructed 
(fig. 8-18), for those most likely vowel equivalents. 
This line may be constructed like the consonant 
line, or as a simplified form given below. In either 
case, the intent is to tabulate the contacts of the 
vowel equivalents, having in mind the characteristic 
of a vowel contacting a consonant more often than 
it contacts another vowel, or itself. 


Luv gbQrstuvwyyz 
NOPQRSTUVHXKY2Z 


Figure 8-18 EK Vowel equivalent line (U). 


8-20 


_GONFIDENTHAL—— 


CONFIDENTIAL __ 


d. Examination of the Qc vowel-equivalent line 
reveals that He, Ic, Je, Ve, and Xe are probably 
consonant equivalents. The Sc line tends to confirm 
the Je and Xe consonant-equivalent assumption, 
and also indicates that the Ec may also be a con- 
sonant equivalent. The He line confirms Ec, He, Je, 
and Xe as probable consonant equivalents, and also 
indicates that Ye may also be a-consonant equiva- 
lent. Thus far then, the following assumptions 
appear logical: 


Vowel Equivalents: Qc, Sc, Re 
Consonant Equivalents: Ec, He, Ic, Je, Ve, Xe, 
and Ye 
If the above assumptions are valid, only the Ze of 
the questionable vowel equivalent is actually a 
vowel equivalent. At this point, the analyst resorts 
to a study of the characteristics of vowels and 
consonants in combination and relation to one 
another to discover the correct plaintext equivalent 
for each cipher value. : 


CONFIDENFHAL_ e-21 


CHAPTER 9 ih 


MULTILITERAL MONOALPHABETIC SUBSTITUTION SYSTEMS 


-Section |. (C) CHARACTERISTICS AND TYPES 


9-1. (Klnkroduetion 
a. Monoalphabetic substitution is classified into 


either uniliteral or multiliteral. In the former, there 
is a strict one-to-one character relationship between 
the units of the plaintext and the units of the cipher- 
text. A multiliteral monoalphabetic substitution 
cipher, on the other hand, is a cryptographic system 
that produces ciphertext units of two or more 
characters for each cquivalent character of the 
plaintext. 

b. The term multiliteral is used in cryptography 
in its broadest sense. It is applied to those systems 
which exhibit a constant relationship between one 
ciphertext unit and one plaintext unit, regardless 
of whether the system employs letters, numbers, or 
special symbols as.-the ciphertext character. For 
specific reference, multiliteral systems are classified 
by the number and type of ciphertext characters 
_used to replace each plaintext unit. 

(1) Biliteral refers to systems involving the use 
of two-letter ciphertext units. 

(2) Triliteral refers to systems involving the 
use of three-letter ciphertext units. 

(3) Dinomic refers to those systems involving 
the use of two-figure ciphertext units. 

(4) Trinomic refers to those systems involving 
the use of three-figure ciphertext units. 


fe 2. DG. -E 


ALBici DI Ez 
Zi Mint ole 
Qt Rist rl ul 


CRe = Ap 


WHR WO 


Figure 9-1 


468-095 O-72-38 


c. Multiliteral systems in general represent an 
attempt to offer greater security than the simple 
uniliteral cipher systems. Onee the principle of 
solving uniliteral substitution systems by the 
analysis of the plaintext characteristics reflected in 
the ciphertext became known, the cryptographer, 
sought methods that would either disguise, suppress. 


-or eliminate these characteristic frequencies or 


patterns in the ciphertext. Among the nuultiliteral 
systems developed are simple biliteral systems, 
biliteral systems using variants, and multinomic 
systems. 


9-2. (Z) Simple Biliteral Substitution 

a. Ift simple biliteral substitution systems, figure 
9-1, the ciphertext unit to plaintext unit ratio is 
a constant 2 to 1. Thé ciphertext unit is either a 
letter or number, with its identity having little or 
no effect upon either the cryptographic process or 
the cryptanalysis of the ciphertext produced. 
Generally, these systems are based upon a matrix 
which contains the plain component alphabet. 
Row and column coordinates form the ciphertext 
units which are substituted for each plaintext 
value. Note that to fit the alphabets to the dimensions 
of the matrices, the I and J are combined into a 
single cell in the first; the IT and J. U and V are 
combined in the second matrix. 


Bieta Li ol Ri yi yi 


3le = Ap 


. Simple biliteral substitution systems (U). 


CONFIDENTIAL : -1 


GONFIDENFIAL- 


b. In figure 9-1, the plaintext component is limited 
to 25 and 24 characters respectively by combining 
certain values which could be used interchangeably 
without causing a loss of intelligibility. Encryption 
in either of the systems is the same. The plaintext 


S EN D RE I 


N F O R C EM EN T 8S 


equivalent is located within the matrix, and the row 
and column coordinates indicate its position in its 
ciphertext value. For example, the message below 
could be enciphered as shown: 


X X 


SDCEEDCG SICERGEDRREGSICDCEEICEEDSGSD TDTD 
SDCEE DCGSI CERGE DRREG SICDC EEICE EDSGS DTDTD 


or 
SEND REINFORCEMENTS XX 
16223532 26221335 1225261 1221422353716 3838 
16223 53226 22133 51225 26112 21422 35371 63838 


c. The process of decipherment is the reverse of 
the process of encipherment. The ecryptographer 
breaks the ciphertext into digraphs or dinomes and, 
using these as coordinates, locates their equivalent 
plaintext value. Note that in these particular sys- 
tems, the order of selecting the row and column 
coordinates as ciphertext values must be predeter- 
mined as row and column or as column and row. 
Normally the former system, similar to reading 
map coordinates, is used. 

d. The biliteral and dinomic alphabet produced 
by the system illustrated above is also termed bi- 
partite, as each cipher element can be divided into 
two distinct parts, each having a clearly defined 
function as row or column coordinates. On occasion, 
the systems illustrated are termed bipartite systems 
due to the nature of the cipher alphabet produced. 


e. It is obvious to the analyst that these particular 
systems offer little or no difficulty. Essentially, the 
process does not effectively disguise either letter 
frequency or word pattern. Further, the bipartite 
nature of the alphabets produced by these systems 
is one of their weaknesses, making them easy to 
recognize by the analyst. In effect, the foregoing 
system does nothing more than double the length 
of the ciphertext, offering little more security than 
the uniliteral monoalphabetic substitution system. 
To circumvent these weaknesses, multiliteral sys- 
tems employing variants were developed. 


9-3. (Y Biliteral Systems With Variants 

a. In a basic biliteral system, a given plaintext 
value is always replaced by one constant ciphertext 
element. Each time that letter is used again, the 
same ciphertext element appears. The biliteral sys- 
tem with variants is an attempt to provide variant 
ciphertext values for each plaintext value, thus 
suppressing the appearance of letter frequency and 
word patterns in the ciphertext. There are two basic 
methods whereby these variant values are intro- 
duced. The first, using subterfuge, results in a 


pseudovariant which only camouflages the true 
biliteral nature of the alphabet. 

(1) One such method is to construct the matrix, 
including row and column coordinates, in such: a 
manner that the resulting cryptogram resembles 
other systems. For example, using the matrix in 
figure 9-2, messages could be enciphered, and when 
the ciphertext is divided into five-letter groups, it 
gives the appearance of code groups. 


BCODFG 


SOK 


R A TI D 6S 
OC AB EF AF OD 


Figure ard Artificial code language matriz (U). 


(2) Another method is to add additional digits, 
thereby disguising the bipartite nature of the alpha- 
bet. For example, where the ciphertext is composed 
of dinomic elements, a ‘‘sum-checking’’ digit which 
is the noncarrying sum of the two digits of the 
element may be used. The cryptogram produced by 
the dinomic system previously illustrated could be 
changed to appear as a trinomic system by the 
following operation. 


CIPHERTEXT 

16228 53226 22133 51225 26112 21422 35371 63838 
1+6=7 167, 2+2=4 224, 34+5=8 388, ete. 
CIPHERTEXT AFTER SUMMING DINOMES 
16722 48583 25268 22413 48581 28257 26811 22241 
46224 36837 01678 81381 


(3) Even a set of randomly selected characters 
may be used, inserted following each digraph or 
dinome solely for the purpose of confusing the 


3 CONFIDENTIAL 


7 | 


analyst. But here, as in the two preceding examples, 
little is gained. In the first case, the limitations in 
the values used soon reveal the system as simple 
multiliteral, and the bipartite nature of its alphabet 
makes analysis easy. This is also true with the 
second case, and additionally, this particular method 
results in one plaintext element being replaced with 


VWXY 2 


fed 
SNE hy 
moO Q web 


Lod 


WG O35 


Figure 9-3 ( 


ce. The matrices in figure 9-3 represent some of the 
simpler means of accomplishing biliteral substitution 
with variants. Each is disguised by one or more 
characteristics representative of biliterals with 
variants. 

(1) Note that example 1 provides six possible 
variant cipher elements for each plaintext unit. Ap 
could be represented by any one of the cipher 
digraphs KV, KQ, FV, FQ, AV, or AQ. 

(2) Example 2, which is an extension of the 
pseudovariant system shown in paragraph 96(1), 
now provides four variants for each plaintext element. 

(3) Example 3 illustrates a method of providing 
a number of variants approximately equal to the 
normal frequency of occurrence of a given plaintext 


three ciphertext characters— an inordinate increase 
of message length for security gain. 

6. By far the simplest practical method of intro- 
ducing variants into a tmultiliteral substitution sys- 
tem is by the us- of additional row and column 
indicators. Figure 9-3 illustrates some of the possi- 
bilities whereby this can be accomplished. 


AEH JIOU 
TNHB |aéja{cip |e 
VPIC {FiGlHIT IX 
WQKD {[LiMINIC PR 
XRLF {ofrls|z [a 
zsaeeo V[wiepi{a 
(2) 

Og 

16 

21 

c7 

ars) 


123456783 
PTJETRIMIT UT IAI LIS | 
BICIDIFIGIELIIKIO| 
BODE 
L243 {4 [5 Je} 7 $819 13 | 


(5) 


. Multiliteral systems with variants (U). 


letter. Thus Ep may be replaced by 25 different 
cipher equivalents, while the Kp is replaced by 
only two. 

(4) Example 4 illustrates that a biliteral alpha- 
bet need not be a bipartite. No single element 
exclusively indicates row or column, i.e. the digit 1 
indicates two rows of one column. 

(5) Example 5 illustrates a method of providing 
for the normal frequency of usage of the plaintext 
letter, this time based upon a key word composed of 
high-frequency letters. ft also provides for the use of 
digits rather than requiring that they be spelled out. 

(6) Note that encipherment using matrices 1 
and 2 are commutative; the coordinates can be read 
in any direction and the same plaintext letter is 


CONFIDENTIAL —— 9-3 


always found. For example, in matrix number 2, BAc 
and ABe both equate to Ap. All other matrices 
illustrated are noncommutative; therefore, the method 
of indicating and reading out the plaintext letters 
must be agreed upon in advance. For example, in 
matrix 3 the cipher element BD may indicate Fp or 
Cp depending on whether the order is row-column, 


or columyyrow. 

9-4, is of Multiliteral Monoalphabetic 
Substitution 

The obvious disadvantage of all such methods dis- 

cussed in the preceding paragraph is that the crypto- 


graphic text is exactly twice as long as the original 
plaintext. Moreover, there is no great compensating 
advantage from the standpoint of security in most 
cases. It is possible that the number of variants is so 
extensive that the system’s overall security could be 
improved, but any such scheme would entail the 
risk of error in the encryption process. It has been 
shown through experience that when given a number 
of choices of variant values, the cryptographer will, 
over a period of time, tend to use only a very few of 
those available. Thus the provision of variant values 
by the system can be largely forfeited. 


Section Il. (X ANALYSIS OF MULTILITERAL SYSTEMS — 


9-5. Introduction 

a. The analysis of simple multiliteral systems and 
multliteral systems with variants, whether dinomic 
or biliteral, involve certain similar techniques and 
methods. Although the more complicated variant 
systems may require the use of techniques particular 
to their case, the underlying principles are similar. 
Accordingly, those general principles will be ex- 
plained and demonstrated in this section. Those 
special techniques applicable to specific cases will 
be developed in the succeeding section. 

b. The analysis of all multiliteral systems may 
take one of two general courses. One method which 


Message 


ATTACK TO BEGIN AT ZERO SIX ZERO 


Ciphertext 


can easily be employed in the case of a simple 
multiliteral system, and which under certain cir- 
cumstances can be used in the case of multiliterals 
with variants, is the solution of the literal values 
as though they were monographic. This is done by 
using the same approach as for the analysis of uni- 
literal monoalphabetic substitution. To demonstrate 
the basis for this particular approach, examine the 
cryptogram given below. Herein, it can be seen that 
the ciphertext, produced by the system illustrated 
in paragraph 9-2, exhibits the same pattern repeats 
and letter frequencies as does the plaintext. The only 
difference is that the ciphertext exhibits this pattern 
digraphically rather than monographically. 


ZERO HOURS TOMORROW XX 


CRSGS GCRCD RESGE GCICE RIRGE DCRSG 
TECES IEGSD RGTDT ECES! EGTEC ESTEG 
RDEGS ESISD SGEGE TEGS!SItEGT ITDTD 


c. When the message above is reduced to uniliteral terms, the word patterns of the underlying plaintext 
seem to leap out. 


A B B A 

CR S@ SG CRCD RE SG EG CI CERI RG ED CER SG 

A B Cc OD A B C D A B CD 

TE CE SI EG SD RG TDTECE SI EG TE CE SI EG 
A B A C C A 

RD EG SE SI SD S@ EGE! EG SI SI EG TI TD TD 


d. The second general approach involves the si- 
multaneous analysis of the ciphertext for plaintext 
values and the recovery of the matrix. This approach 
may be used for either the simple biliteral or the 
biliterals with variants. It is more appropriate in 
the case of the latter system, for all variant forms 
of each cipher element must be identified prior to 


the reduction of the cipher elements to uniliteral 
terms. 

e. Prior to the start of any analysis, however, a 
system must be identified as to general class and 
wherever possible to the specific type within that 
class. In the following paragraph, methods of identi- 
fying multiliteral systems are treated in detail. 


4 CONFIDENTIAL 


CONFIDENTIAL 


9-6. (4) Identification 


a. The identification of a biliteral system is much 
easier than the identification of some uniliteral 
substitution systems. This is particularly so in the 
case of the simpler forms of the biliteral system. 
Normally, the initial basis of identification lies in 
the recognition of the textual limitation imposed by 


the number of characters used as row and column 
indicators and their manner of use. Where the indi- 
cators are limited in number and are bipartite in 
nature, identification of the system is quite easy. For 
example, 4 uniliteral frequency distribution of the 
following ceryptogram would hardly be necessary, as 
the limitation in the number of letters used is obvious. 


AHARE SSEER ARCSC 
ARAOC SAECH ARAEP 
SSASP ESSAE CRSEA 
AEAEA RCRCH SSCHC 


RSHSS CHCHS SASPH 
OSSCO SEASP HAOSE 
ESSCR SECHA RCOCS 
HSSSO PSJIJJI 


The briefest examination reveals that aside from the 
three J’s appearing at the end of the message, these 
probably being nulls, there are only eight different 
letters used, the letters .1, H, R, E, 8S, C, P, and O 
respectively. If the message is divided into digraphs 
and another count is made, a definite positional 
limitation would be observed. The letters 4, E, S, 
C, and P would be found in the first position and the 
letters H, R, S, EH, and O would be noted in the last 
position. On the basis of these limitations, the 
analyst could safely assume that the message repre- 
sents a case of multiliteral encipherment. 

b. A close examination of the message reveals 
several other features which are characteristics of 
multiliteral systems in general and which may also 
be used for identification purposes. 

(1) The number of the letters or digits in the 
message, excluding nulls if they are added after 
encipherment of the plaintext, is a multiple of the 
cipher element. In the example above, there are 112 
letters, or 56 digraphs. Conversely, the length of the 
cipher element can sometimes be derived from 
message length, for example, a dinomic system using 
sum checks. In any event, the analyst immediately 
explores this possibility. 

(2) The number of letters or digits in repeated 
series are the same in each case and are a multiple of 
total message and cipher element length. For 
example, in the message above, two repeats occur: 
RSHSS CHCHS SASPH and SSCHC HSSSO, 
which are equal in length, 8 letters or 4 digraphs long. 

(3) The number of letters between repeated 
sequences, between the beginning of the message and 
occurrence of first repeat, and between the end of the 
last repeat and the end of the message, are all 
multiples of two. For example, there are 18 letters 
before the first repeat. The repeat contains 8 letters. 
Following it, there are 74 intervening letters, again 
the 8 letters are repeated, then 4 letters to the end 
of the message. Each interval is a multiple of 2; 
hence, this is the cipher element’s size. 


9-7, Statistical Tests 

a. Just as the Phi (#) and the Index of Coinci- 
dence (1.C.) tests can be applied to a cryptogram to 
determine whether it is monoalphabetic, so also can 
variations of these same tests be applied to the 
digraphic distribution of a cryptogram to determine 
whether the cryptogram in question is monoalpha- 
betic when considered as a multiliteral cipher. The 
basis for the application of these tests lies in the 
uniliteral nature of simple multiliteral substitution 
and the limitations inherent in a multiliteral with 
variants which make it susceptible to these tests. 

6. In foregoing chapters, both the @ and the LC. 
tests are explained in terms of their application to 
uniliteral monoalphabetic substitution. The general 
form of the tests when applied to digraphic distribu- 


tions remains unchanged though the values are now 
different. The plain and random constants and the 
“N”’ in the formulas now pertain to the number of 
digraphs under consideration instead of the number 


of single letters. The formulas are shown below: 
(1) Digraphic Phi test, (24). 
2¢0= Sf(f—1) 
2p =.0069N(N—1) 
2or=.0015N(N—1) 


f=Number of occurrences of each 
digraph 
N= Number of occurrences of all digraphs 
(=F) 


(2) Digraphic 24I1.C. test. 
L.C.==rC—(f—1) 
N(N—1) 

C=The number of possible digraphs, 
i.e. the number of letters in the 
alphabet squared. For English 
C=26x26=676. 

N=Number of 
digraphs. 

f=Total number of occurrences of each 
digraph. 


occurrences of all 


CONFIDENTIAL 9-5 


CONFIDENTIAL 


(3) The digraphic I.C. can also be determined 
by comparing the value of observed occurrences to 
the value of expected random occurrences, with the 
I.C. being expressed in terms of a ratio between the 
two values. The formula for this test may be ex- 
pressed as: 


L.C.=2¢0 
2or 


In the case of digraphs, the I.C. for English plain- 
text is 4.66 and the I.C. for digraphic English 
random text is 1.00. 

c. These foregoing tests, as all statistical tests, 


are subject to a degree of error, depending upon the 
makeup of the cryptographic test being studied. 
Specifically, in the case of multiliteral systems the 
presence of repeated groups, the limitations in the 
number of different digraphs present, and the size 
of the sample itself all tend to distort the test 
results. Therefore, they must always be used with 
caution, with the preferential method being to 
employ them in conjunction with other evidence for 
identification purposes. 

d. The first step in using any of the test steps is 
to tabulate the frequencies of all digraphs comprising 
the message, and to determine the individual value 
of f(f—1). This may be done as follows: 


WU EMT 


WMTST SWMIM BOIST SWMWU MHMTE EMIUE 
MHUTE TMEMW OEMIU ISTOW EEMEU TUIST OTSTO 
TUIUI SHSEM WSESE MISTS WMHSH UTUHS ISESE 
UEUTU HSTST STUHM HSEMW MIMIO WUTOI UEMXX 
WMWU WO WE WS TS TMTE TO TU IU IS IM 
f 5 3 1 1 1 7 2 2 4 5 4 6 2 


ff—~1) 20 6 0 0 0 42 


2 2 12 20 12 = 30 2 


EO EM EU ES HS HM HU 


1 10 3 2 5 2 
0 90 6 2 20 2 


(1) Using the values determined above, the 
values of the 2¢ test may be computed as follows: 
2¢0=Zf(f—1) =270 
2¢p=.0069N (N — 1) =.0069 X 69 X 68= 31.5478 
2or=.0015N(N—1)=.0015 X69 K 68 =7.0380 


(2) The 2¢ I.C. may be computed as follows: 


C f(f—1) _676X270_ 182520 _ F 
N(N—1) 68X69 +4692 ~ 


(3) And the second method of determining a 
digraphic I.C. may be computed as follows: 


2 1.C. = =. =38 


e. Note that in the case of the computation of 
2 LC. above, the value derived is in the value range 
of 31 to 43. In the case of the biliteral system the 
expected values for a simple biliteral fall in the range 
of 20 to 40, and the expected values for a biliteral 
with variants is 6 to 20. The extremely high difference 
in value computed for the digraphic Phi test lies in 
the fact that the test involves a comparison between 
an expected occurrence based on the possibility of 


2 xf=N=69 
2 xf(f—1)=270 


676 different digraphs used in plaintext, against the 
actual occurrence of only 69. 


9-8. (BS Analysis of Biliteral Systems 


a. Once the system has been satisfactorily identi- 
fied, the analysis of the system may commence. 
The analysis may include the simultaneous attempt 


to recover the matrix and the establishment of 
plaintext values for the cipher elements. 

(1) In the first case, use is made of the number 
and positional limitations of the cipher elements. 
For example, a tabulation of the letter comprising 
the foregoing message reveals that only nine differ- 
ent letters (W, M, T, 8S, 7, E, O, H, and CU respec- 
tively) were used. Further examination quickly 
reveals that there is a definite positional limitation 
involved. The letters W, 7, J, EZ, and H occur in 
the first position and the letters M.S. O. U. and 
appear in the last position. The number of the letters 
involved and their positional limitation immediately 
suggests a 5 x 5 matrix of 5 cells by 5 cells with 
these letters as row and column indicators. Accord- 
ingly, a matrix of this configuration figure 9-4 is 
set up: 


W 


Wy 


Figure 9-4 (C). Preliminary matrix with row and column 
indicators (U). 


(2) Note that the dimension of the assumed 
matrix is determined by the composition of the 
cipher elements. This step presupposes the correct 
identification of the cipher unit and correct inter- 
pretation of their positional significance. At this 
particular point it matters little if the row and 


column indicators are reversed, for a simple turn 
of 90° will correctly realine the indicators. 

b. After identifying the row and column indi- 
cators and determining the matrix dimensions, the 
next step is to insert values into the cells of the 
matrix. It is at this point that use is made of the’ 
uniliteral nature of simple multiliteral substitution 
by reducing the digraphs to uniliteral terms. This 
may be done very easily by substituting a letter 
for each different digraph appearing in the crypto- 
gram. If not more than 36 different combinations 
are present in the cryptogram, the extra values 
above 26 may be represented by digits. As a general 
rule, where less than 26 different cipher elements 
are encountered, it is advisable to reduce them to 
uniliteral terms. This permits the construction of a 
triliteral frequency distribution, and use of all other 
studies associated with the analysis of monoalpha- 
betic substitution. 

(1) For this purpose the tabulation of digraphs 
previously made may be used. Using this tabulation, 
one letter is assigned to each different cipher element. 


WE WMWOWS WU TS TM TE TO TU TU TS IM IO 


Ay B.-@ * DD. 2B oF 


This process results in a pseudoplaintext which 
reflects all the underlying characteristics of the true 
plaintext. Inasmuch as the same characteristics are 
exhibited by the ciphertext elements, there may be 
some question as to the need of this step. The reason 
for this is twofold; first, it permits the differentia- 
tion of the row and column indicators and the 
plaintext letter they represent (useful in the re- 
construction of the matrix), and second it provides 
a suitable element for manipulation in applying the 
technique of solving monoalphabetic substitution 
systems. While this factor is not of any great impor- 
tance in relatively short cryptograms, it is very 
helpful where many cipher elements are under 
study. 

c. With the digraphs reduced to uniliteral terms 
and having an assumed matrix, the recovery of the 
plaintext may begin. In this step the frequency 
distribution of the pseudoplain values may be 
studied individually and fitted to the normal to 
recover their true plaintext values; or the message 
text may be scanned for word patterns and then 
compared to the frequency distribution for identifi- 
cation of plaintext letter values. In all cases, when 
a plaintext value has been recovered, it may be 
inserted in the matrix at the point of intersection 


G H It J K LM N 
EO EM EU ES HS HM AU 
O P Q Rk SS T U 


of its cipher row and column indicators. This per- 
mits the simultaneous reconstruction of the matrix. 
and if it shows any symmetrical pattern, allows the 
placement of additional plaintext values, thus 
hastening the final solution. The eryptogram, re- 
produced in terms of the arbitrary uniliteral values 
previously assigned, now appears in figure 9-5 with 
significant repeats underlined. 


BFPBMOLFBEEPGTHPKP 
UH GP CP KEL LAP Od bh LF LT a 


KLESPDORPLFBSUSSLROS 


JSFFJITSPBHUNMNETIKP 


Figure 9-5 (C). Ciphertert prepared for analysis (U). 


(1) The patterns .1BB.l-- and .ABsL -—— for 
the sequence BFFBM and PKPUH are suggestive 
of the words .AT TACK and ENEMY respectively. 
Accepting these assumptions for the moment, the 
plaintext values are inscribed in the matrix using 
the appropriate cipher diagraphs as row and column 
indication. 


’ 


CONFIDENTIAL — 7 


POA OT - oF AY OK 
P-P B F F B M O 
C WMTS TS' WM IME 
: M 
W A 
T 
I e¢ 
BE EF 
H 


(2) Analysis continues in the same vein as 
above, i.e. by attacking the characteristics of the 
ciphertext itself. However, in this case, sufficient 
evidence is at hand to attempt recovery of the 
matrix. Note that the first column in the matrix 
contains the first and terminal letters of the first 
five letters of the alphabet (ABCDE), suggesting 
the @ and D are the correct values for the blank 
cells. If this is the case, presuming the letters to be 
inscribed in alphabetic order, the sequence of the 
row indicators are out of order; E, as EMc=Ep 
must be last, and T and H of the row indicators 
must then lie in either the second and fourth, or 
fourth and second positions respectively. Assuming 
the latter, the word WHITE is noted; therefore, the 
matrix is rearranged accordingly (fig. 9-6) and B 
and C plain are inscribed. 


“eS 0 UE 


BRANES 


Figure 9-6 (C). Insertion of plaintext values (U). 


(3) Examination of the columns shows a good 
alphabetic pattern downward. However, they are 
not in order sequentially; the row containing the T 
follows the .1-E row when it should appear as the 
next to last row. Thus the columns can be recorded 
as follows and missing values assumed (fig. 9-7). 


E N E M Y 
Po: Bo Pe UE ap 
EM IU EM HU TE 
O U E 
Y 
N 
K 
M 
W 
H 
ag 
fh 
E 


Figure 9-7 (C). Solution of matriz (U). 


(4) Using this matrix the message is now 
deciphered logically, proving all past assumptions. 


ATTACK HAS BEEN STALLED BY 
ENEMY DEFENSIVE POSITIONS 
REQUEST ARMOR SUPPORT TO 
BREACH LINE. 


d. The foregoing solution represents an example 
of attacking the message through the system which 
produced it. This is possible only because the system 
was simple; no variants were used. The keywords 
were common and could easily be assumed, and a 
recognizable route of inscribing the plaintext into 
the matrix was apparent from the first. While this 
method for solution is quicker than an analysis of 
word patterns, use of frequency distributions, etc., it 
is not always possible. In such cases, once a multi- 
literal cipher has been reduced to uniliteral terms, 
the most difficult multiliteral ciphers may be suc- 
cessfully solved by the monoalphabetie analytic 
techniques given previously. 


Section Ill. (ANALYSIS OF MULTILITERAL WITH VARIANTS 


9-9. of General 
a. In the final analysis, the simple biliteral system 


offers no more security than a uniliteral substitution 
system. To circumvent this obvious weakness, 
variant multiliteral systems are used. The systems 
provide for additional row and column indicators or 
for variant internal values. These enable the substi- 
tution of several different cipher elements for each 
plaintext element. The ratio of cipher elements to 


plaintext elements may now be two or more to one, 
instead of the one to one ratio of a simple multiliteral 
system. 

b. An example of a multiliteral system with ex- 
ternal variants is shown in paragraph 9-3c. Crypto- 
graphically, the method of operation of these systems 
is similar to that of the simple multiliteral system, 
with the exception that the cryptographer now has a 
choice of several values for each plaintext value. 


8 ~GONFIDENTFIAL— 


Using the first and second examples shown in para- 
graph 9-3c, Ap is represented by the cipher elements 
shown below: 


Example 1. KQ, KV, FQ, FV, AQ, AV=Ap 
Example 2. TA, NA, HB, BA =Ap 


To a great extent, the actual number of variant cipher 
elements for a given plaintext letter occurring in a 
cryptogram is dependent upon the cryptographer; 
often the actual number used is limited by failure to 
make use of all values provided. 

c. Identification of multiliteral with variants is 
basically the same as that for a simple multiliteral 
system. The cryptographic text will generally exhibit 
the same characteristics, though perhaps not as 
pronounced. These characteristics are: 

(1) A uniliteral frequency distribution may 
show a limitation on number of letters used, de- 
pending upon the total number of row and column 
indicators used. 

(2) Some positional limitations will usually be 
present with certain letters or numbers appearing 
only as row or column indicators. 

(3) Message length, repeats, and distance be- 
tween repeats will be divisible by the length of the 
cipher element. 

(4) Repeats are likely to be short and frag- 
mentary, and are often composed of several different 
values. 

(5) The 2 ¢ I.C.’s produced by the statistical 
tests will be lower (6-20) than for a simple biliteral 
system. Generally, the shorter the message or the 
less repeats it contains, the lower the 2 ¢ I.C. will be. 

d. Once the variant values of a multiliteral with 
variants system can be equated to specific letters, 
the course of analysis is in all respects similar to 
that employed in the case of the analysis of a simple 
multiliteral system. The cipher units are reduced to 
uniliteral terms; then frequencies, repeated sequences, 


and word patterns are studied for the substitution 
of plaintext values. It is in the former area, the 
matching of the variant values, that different 
techniques are employed. In one technique, the 
structures and frequencies of occurrence of the 
cipher units are studied to identify variant values 
having the same plaintext value. In another tech- 
nique, the approach lies in the study of isomorphic 
repetitions of text for the determination of like 
variant values. Both techniques are amplified in 
succeeding paragraphs. : 


9-10. (a) Frequency Matching of Variants 


a. In the case of a variant system, where the 
total number of variants is limited, matching of 
variant values becomes possible through a study of 
their frequency distribution. This method of matching 
is predicated on the assumption that in a message 
of moderate length, all variant cipher values for a 
given plaintext letter will be used. Further, it 
assumes that each variant will be used with approxi- 
mately equal frequency. Thus, the variant row and 
column indicators for any given letter will appear 
equal in combination with one another. For example, 
the variant values for Ap given in the example in 
paragraph 9-95 can be expected to appear equally 
often. The total number of occurrences of a set of 
variant cipher values will approximate the frequency 
of the plaintext letter they represent. Thus, a definite 
pattern is imparted to the cipher elements which 
can be observed when a digraphic frequency count 
is made in the form of a matrix. Therein, the rows 
and columns correspond to the variant values which 
exhibit profiles equating to the frequency of combi- 
nation of these letters. Where a number of rows or 
columns have a similar profile, a common plaintext 
value for their indicators may be assumed. A 
digraphic frequency count of the message in figure 
9-8@) will appear as shown in figure 9-8@). 


CONFIDENTIAL— 9-9 


CONFIDENFIAL _ 


CATNT 


ALNPI CNDED EGKDO FGAPF DOQBM 
IGECB UOUNQ FLBQB TIDAT NLRPE HILAQ 
AGETB HBPSQ BGICF GFCBIT EGIHO PRGAP 
EPOQK UFPAH ALAMN PKDAU JIHAGS MAQFM 
NQSUB UEDOP ATICO DBHKC AUBUF CSHID 
BGBPK GOQBD KHBIF DFUAT KQAGO MOVED 
WPEUA HKCNC BQECF HBHBL IGBMA UFGIP 
BGKDO CIHNQ SGAPF QSiHSL 

Divided into digraphic elements: 
AL WNP IC ND ED EG KD OC AT WE FG AP #ED 
OQ BM IG EC BU OU NQ FL BQ BI Iv AT WML 
RP EH IL AQ AG ET BH BP SQ BG IC FG FC 
BT EG IH OP RG AP EP OQ kU FP AH AL AH 
NP KD AU TH AG SH AQ FM NQ SU BU ED OP 
AT IC OD BH KC AU BU FC SH ID BG BP kG 
OQ BD KH BY FD FU AT kQ AG OM OU ED NP 
EU AH KC WC BQ FH BH BL IG Bu AU FG 


KD 


SG AP FQ 


Figure 9-8@ oe of ciphertext for digraphic frequency distribution (U). 


& 


by 


Figure. 9-8@) J. Digraphic frequency distribution (U). 


b. A study of the frequency profile may begin 
with either the rows or columns. In either case, it 
is usually better to start with the one which has 
the most pronounced profile, seek a match for it, 
and then move on to the least pronounced. By this 
process of elimination, even the least characteristic 
profile can usually be matched. Note, however, that 
the digraphic frequency distribution represents the 
original’ enciphering matrix in an expanded form 
because its row and column indicators are dis- 


9-10 


associated and disarranged and do not have internal 
plaintext values. Thus, the process of matching 
the profiles will result in the construction of the 
matrix to its original dimension and the reassocia- 
tion of the variant values. In this provess, the analyst 
should be alert to the possibility that some system 
may have been used in assigning the row and column 
indicators. If tnis is the case, a short cut can hasten 
the final solution. 

(1) Examination of the digraphic frequency 
distribution shows four rows which have pronounced 
profiles; they are rows -1, B, &. and F. At first 
glance rows B and F appear similar, but a closer 
examination shows a discrepaney between the fre- 
quencies for FT, FH, FM, FU. FQ, and BT. BH, 
BM, BU, and BQ. Therefore, this match is rejected. 
Considering a match between rows .! and B, a 
much closer correspondence in frequencies is noted, 
thus they may be accepted as a match (fig. 9-9). 


L @ 


mm 


LPC D Pf FT. -8 a 


Figure 9-9 p. Match of rows A and B (UC). 


(2) Because the affinity of rows # to F is not 
particularly negatively or positively pronounced, 
they may be momentarily dropped from considera- 
tion Scanning the rows again, it is quoted that 0 


exhibits an affinity for columns, P, C, D, and again 
for M, U, Q. Excluding rows A. B as previously 
matched, the only other row indicators shown in 
combination are the column indicators Q, N, K, F, 
and S. S can be rejected due to its low profile; K 
has a similar but weaker affinity for U and Q, so it, 


too, may be rejected. This leaves F and N for pos-. 


sible matches to O. Of the two, N seems the most 
logical as both N and 0 are combined frequently 
with P and Q, while F has no high-frequency com- 
bination in common with O. The matrix now appears 
as shown in figure 9-10. 


L PC ODG T EHH U @Q 


Figure 9-10 (fp. Matching rows N and O inserted (U). 


c. The rows above are relatively easy to match. 
Rows <i and B are matched because of their pro- 
nounced profile, and N and O because of similar 
affinities to specific column indicators. Another 
method of determining a match involves computing 
a separate value for each trial match of a row or 
column against the remaining rows and columns. The 
value of each match is derived by multiplying the 
two values contained in adjacent cells of each arbi- 
trary match, and summing their products. The match 
having the highest value may be presumed to be 
correct. For example, E row can be compared to the 
following three possible matches, as shown in figure 
9-11. 


LZ PCGODG T # KUL G& 


E QO i123 23110ii1 +0 
PF 0122402121221 

o 1 & 6 oioilo #21 
E oO 123 21 Oo 1 0 
K 002 3 10210 i1 «0 

oo 4 9 20101 0 =17 
E ) 232110210 


1 

I 113 229 300 #0 
“Oo L 
Figure 9-11 (C). Possible matches of row E (U). 


(1) While all matches are fairly close, the match 
of rows E and F may be tried first. This test, however, 
as all tests, is susceptible to error. Notice how in the 
above a small difference in combinations could result 
in # being almost equally well matched to K or J. 

(2) By a process of elimination. with only four 
unmatched rows left, further matching is quite 
simple. & and 8, both with extremely low profiles, 
are obvious matches, leaving / and AK to be matched. 
At this point the matrix appears is in figure 9-12. 


Figure 9-12 (Pf). Completion of raw matches (0). 


d. The column indicators could be matched by the 
same process used for matching the row indicators. 
This, however, should not be ‘necessary. Notice the 
pattern of the row variants: Le. LB follows sequen- 
tially as does F and F, with a space for two letters 
between. This space is possibly for C and 2), which 
appear as column variants. Thus, C and 2 mav 
represent a match. This possibility is quickly con- 
firmed when the column profiles of the two are 
inspected. Assuming a consistent pattern, the matrix 
can be recovered as seen in figure 9-13. 


Figure ts Ah. Matriz with both rows and 


columns matched (U). 


e. Analysis of the cryptogram bevond this point 
follows the same techniques as those used in the case 
of simple multiliteral systems. The digraphic 
variants are reduced to uniliteral terms by inserting 
an arbitrary plain sequence in the matrix. A distri- 
bution is made, and a study of the frequencies of 
letters and repetitions of patterns in the pseudo- 
plaintext begins. 


_.. CONFIDENTIAL — 9-11 


9-11. icine. Characteristics in Determi- 
~ nation of Equivalents 


a. A characteristic of encipherment by multiliteral 
systems with variants is the disruption of isomorphic 


Simple multiliteral encipherment: 
R E Cc . O M 


SI CE CD EG EI EJ CE ED 


A B C D 


patterns in the plaintext. This disruption may be 
seen in the encipherment of the word RECOM- 
MENDED by the two systems illustrated in para- 
graph 9-2 (fig. 9-1) and example 3 in paragraph 9~3¢ 
(fig. 1-3). 


M E N D E D 


D A E F A F 


Multiliteral with variant encipherment: 


R E C O M 
KK JA DB CA 


6. For all practical purposes, the isomorphic pattern 
of the plaintext word clearly reproduced in the first 
encipherment is completely extinguished by the 
second method of encipherment. If the text of a given 
variant system is scarce, and if all possible variant 
values are fully used and wholly independent of one 
another, the solution can become exceedingly difficult. 
However, in practice this situation is rarely en- 
countered, as practical military communications are 
such that a sufficient volume of text is usually avail- 
able to provide a basis for establishing equivalent 
values. To illustrate the possibilities of determining 
equivalent values by a study of isomorphic repeats, 

_ consider the example below, each set being a series of 
different numeric ciphertext values of one underlying 
plaintext word or sequence of letters. Note that 
although these repeats are useful for analysis they 
first must be isolated from the text as representing a 
probable word or phrase. Usually this occurs in the 
cases where stereotyped beginnings or endings are 
used. In this case, the examples are arbitrarily 
selected for the purpose of illustration. 


Set A 
(1) (2) (8) (4) (5) (6) (7) (8) (9) 
12 87 O02 79 68 18 038 87 77 
82 69 02 79 138 68 23 387 36 
82 69 61 16 18 18 78 O05 36 
91 05 O02 O1 68 42 78 37 77 


Set B 


(1) (2) (8) (4) (3) (6) @ 
71 12 02 51 28 05 77 
11 82 51 02 08 05 35 
11 91 02 O02 28 37 35 


97 12 51 O02 78 69 77 


c. Examination of individual cipher sequences in 
each set shows no isomorphic pattern other than a 
few scattered repeats. However, inspection of the 
columns formed by the superpositioning of the cipher 
sequence reveals that in columns (3) and (4) of set B, 


9-12 


IC DL MJ AG 


M E N D E D 
IF JA DJ 


the dinomes 5/ and 02 are used exclusively and inter- 
changeably. In column (3) of set A, the dinomes 51 
and 02 are also used interchangeably, but in column 
(4) different dinomes appear. A close study of each 
column leads to the acceptance of the following 
groupings as possible equal cipher equivalents: 


12 37 02 79 68 03 77 71 
8% 69 51 16 18 23 35 11 
91 06 O1 42 78 a7 


d. The equivalent values derived above may be 
assigned arbitrary values to reduce them to uniliteral 
terms. Thereafter, these equivalencies may be used 
to find additional sets of equivalent values in the 
ciphertext. The analyst may recover plaintext letters, 
by applying the method of the analysis of probable 
words and word patterns, and then proceed to 
analyze the uniliteral terms in that light. For example, 
the sets of cipher equivalents could be reduced to the 
following word pattern: 


Set A 
(1) (2) (3) (4) (5) (6) (7) (8) @) 
12 87 02 79 68 138 O08 37 77 
82 69 02 79 18 68 23 37 35 


82 69 51 16 18 13 78 O05 35 
91 05 O02 O1 68 42 78 37 7 
A B C D D E A 


Set B 
(1) (2) (3) (@) (@) ©) @) 
71 12 O2 S51 23 O58 77 
11 82 51 02 03 O58 35 
11 91 O02 O2 238 387 35 
97 12 &1 02 78 69 77 
A A 


e. Besides the isomorphic pattern of the words 
themselves, the indication that certain letters are the 
same is of value in determining the exact words 
these patterns represent. The fact that the dinomes 
of column (3) in set A and those of columns (3) and 


CONFIDENTIAL— 


“GONFIDENTIAL _— 


(4) in set B are similar was previously mentioned. An 
examination of the grouping of possible cipher 
equivalents also shows that the last three letters of 
both words have the same plaintext value. Using the 


- ABCDODEA 
ARTILLULER 


jf. The determination of equivalencies may appear 
to be an easy matter, as is their extension to probable 
words. However, it may be very difficult, as the 
cryptanalyst can never be certain that a set of cipher 
sequences showing what appears to be the use of 
variant values to encipher the same plaintext word 
or phrase is correct. There is always the possibility 
that they are parts of different plaintext sequences. 
For example, the cipher sequence on the surface 
represents the same word with two variants appear- 
ing in the first position. 


17 82 81 82 14 68 
27 88 40 88 138 63 


However, it could as easily represent the different 
words MANAGE and DAMAGE or other similarly 
constructed words. 


9-1 2. (Ff Analysis of Isologs 


a. Occasionally in military communications, a 
situation occurs where one plaintext message is 
enciphered in either.two different systems or vari- 
ations of the same system. The cryptogram thus 
produced, differing in ciphertext but having the same 
underlying plaintext, is termed an isolog. Isologs, no 
matter how produced, are among the most important 
means available to the cryptanalyst in solving a 
cryptogram. In some instances, isologs are the only 
practical means of entering systems which offer no 
other clues. Such an entry proves useful in multi- 
literal systems employing variants where conditions 
preclude the application of techniques previously 
discussed. 

b. Normally an isolog is recognized by equality, 
or near equality, of length of two or more messages. 
An isolog may be suspected where this similarity of 
message length is noted. However, before accepting 
this cor dition as fact, a confirmation in similarities is 
sought in those elements pertaining to handling and 
transmission of the message, such as, serial numbers, 
originators, etc. Also, if the isolog is generated by the 
use of variations of the same system, a few scattered 
repeats may be noted throughout the message. It is 
an isolog of this nature that provides a means of 
solving multiliterals with variants. 

c. Regarding the analysis of isologs and isologous 


word patterns and the expected similarity of letters, 
a word pattern list cun be scanned for words which 
conform to these conditions, resulting in the discovery 
of the words: 


- ~A A -~- | 
BATT ERY 


segments of multiliterals with variants, the technique 
employed is only an extension of the methods used 
in the determination of equivalent values by a study 
of isomorphic characteristics. The only difference is 
that in this case the whole message as an isolog, or 
large portions of it as isologous segments, are studied. 
Moreover, the study of word patterns and the deriva- 
tion of probable words may involve whole phrases 
rather than individual words. 

d. Given two messages suspected of being isologs, 
a digraphic distribution is made for each in figure 
9-14@) and 9-14@) and examined for any character- 
istics which might aid in the analysis of the erypto- 
gram. The messages and their respective distributions 
follow. 


Message A 


A 82260 63108 74839 69842 
32029 70118 80277 89106 
B 94000 13828 0¢082 40060 
63629 33918 43156 81048 
C 26408 45039 - 81718 02558 
73309 20749 61796 16476 
D 38728 91147 29926 41468 
13366 83681 89697 J8816 
E 017850 07074 11804 45200 
28120 277680 81139 72962 
F 27868 606068 30870 40867 
46594 19800 | lv8é2 26987 
G 40729 36248 


12345678399 


2 {aja tat2tat-12 [2] 2] 
i jaf-|ipitefele ja} -| 
ABBERRenAaa 
a tafalafereyaia jit —| 
a fat2tatete| —l-[ii2) 
TiRARERaAe 
i fetateyetat ay ata) 2 
2t2tataj-japeti fet 2) 
i fetetaj-jile} 2 fel a) 
BERR eBeeee 


Figure 9-14@ (Y). Digraphie frequency distribution, message 
A (UV). 


Bwlewmn ee WW hw 


GONFIDEN HAL —__ 9-13 


Message B 


2 10 15 20 


At 30100 87497 14611 97360 
49676 00106 45647 99181 
B! 69672 03889 41063. 25203 
90628 77886 = =620301 10670 
C* 89277 70011 60199 90138 
99974 60232 04116 89216 
Dp! 384638 17547 14648 00646 
80864 53898 26121 83878 
E! 94889 83728 11272 20004 
06484 $2103 98718 426602 


Fr 30760 39880 441065 52900 é. As both dinomic distributions reveal a random 
59728 22855 87300 70893 scattering of frequencies with no single pronounced 

Gt 57682 46253 pattern in either row or column, multiliteral s¥stems 
with variants may be assumed for each. Further, 

1234567899 although the distributions are flat, they are very 


similar in respect to the location of both blanks and 
points of high frequency. [t may. therefore, be tenta- 


1 [hate [2 fa [2 [-[2[ 2] a) See eed 
9 BBESAAAGEE ivel astra uit the two messages are eueirpns 
3 TTD sri 7 of one system, An examination of each message 
4 reveals no single outstanding characteristic which 
5 indicates the underlying plaintext or system of 
6 encryption. Therefore, the messages may be com- 
> pared to each other to determine if any such pattern 
8 exists, and to further their identification as isologs. 
9 BeEGEEEBE This is done by inscribing one above the other, 
g Beane assigning row and column coordinates for reference 
purposes. Because the system involved is multiliteral, 
Figure 9-14@ (Qh Digraphic frequency distribution, message the text is arranged in dinomic elements. as shown 
BU). in figure 9-15 

5 10 15 20 

A 2 26 86 81 03 74 83 96 J8 ge EL $2 97 01 15 80 27 78 31 O68 

A' 30 15 08 74 97 14 51 1) 75 co 42 6? 65 01 16 4&8 64 79 91.81 


i 27 86 56 U6 23 90 87 04 UE G7 dU oD 41 98 55 10 82 22 29 87 


es ota GONFIDENTIAL— 


GONFIDENFIAL 


jf. When the paired digraphs formed by the super- 
imposed messages are scanned closely, several 
digraphs are repeated at the same position in each 
message. Some of the repeats are: 


(14) (19) (6) (20) 
o1 91 E 11 62 

A’ ari 91 E’ 11 62 
(4) (12) (15) 

B 38 62 F 56 

B’ 38 62 Fr’ 55 
(4) (10) (4) 

Cc 50 38 G 62 

C’ 50 38 G’ 62 


(1) (5) (14) (19) 
D 88 47 88 38 
D' 88 4% 388 38 


The repeated occurrence of the same dinomes in 
both messages at the same relative position, always 
paired and also coupled with the similarities in the 
frequency distribution, is strongly indicative that 
the messages are produced from the same encipher- 
ing system. The fact that certain values are paired 
while the intervening dinomes between appear 
random may be explained by the assumption that 
the system provides a number of variants for high- 
frequency letters and few or none for low-frequency 
letters. Thus, the plaintext value for the dinomes 
paired in both messages could be low-frequency 
letters. Further, if this is the case, the dinomes 
appearing in both messages between a set of pairs 
must then represent the use of variant values to 
encipher the same plaintext sequence. 

g. Using the foregoing assumption as a base, it is 
possible to form a chain of possible equivalent values 
by equating dinomes to each other. For example, the 
first six sets of dinomes of each message may be 
written vertically as follows: 


Message A A’ 


82 380 
26 165 
56 08 
31 74 
03 97 
74 14 


As it has been assumed that these dinomes are equal 
values for the same plaintext letters, it then follows 
that if any one of these are found paired with 
another dinome then it too must represent the sume 
value. For example, in position A A’ (4) and (6) the 
paired dinomes 31 74 and 74 14 are found. If 74 is 
related as equal in plaintext value to 31, 14 must 
also be equal in value to 31 and 74. Thus a sequence 
of 31 74 14 may be desired. By continuing the 
same chaining process on a reciprocal basis (possible 


because both messages are enciphered by the same 
matrix), the following chain of equal values, figure 
9-16, is derived, arranged in order of length. 


06 14 15 26 28 31 35 73 74 81 89 98 ay 
02 07 20 22 43 44 63 30 

12 87 48 51 69 70 83 34 

03 30 41 54 65 82 97 

05 10 € é 49 87 33 

1€ 18 36 76 78 73 8 


Figure 9-16 (C). Chain of equal values (UU). 


h. The equivalent values produced by the chaining 
process can now be assigned arbitrary Ictters to- 
reduce them to uniliteral terms, and each message 
can now be studied on these terms. Not only will 
word patterns come to light when the uniliteral terms 
are substituted for the dinomes, but also since the 
system apparently made provision for hich -frequeney 
letters, they in turn can be identified by the number 
of their variant values. For example. the first chain 


- above probably equates to E of the plamtext. Using 


the assumed E value and the list of equivalent values, 
a sequence of word patterns and their partial plain- 
text values is easily derived. For example: 


A 82 26 56 81 08 74 83 96 98 42 32 52. N7 O1 

A’ 380 15 08 74 97 14 51 19 73 BO [4 ur BS Ol 

P - E- E- E- - B- - - = = 
ABCBABDEBFGH A 


Then, comparing this to a list of word patterns, all 
the other plaintext values could be determined. For 
example, the first eight letters of the pattern probably 
mark a whole word. A similar pattern which contains 
an E in the appropriate positions is the word REFER- 
ENCE which can easily be expanded to REFERENCE 
YOUR for the whole isologous sequence. With a few 


_ known values for the arbitrary uniliteral term, the 


solution of the remainder of the message poses no 


CONFIDENTIAL — 9-15 


CONFIDEN FAL —— 


particular difficulty, and the enciphering matrix 
could be recovered as shown in figure 9-17. A word 
of caution though, this method is not always 100 per- 
cent certain. In some cases mistakes made in trans- 
mitting or copying the message and also the lack of 
values may prevent the chaining process from being 
carried through. 


123845678399 


DIN HIELE|A{-|Alclo| 
I[T/-fo[Mlz|sjetr iT 
EPO] -|-JEJAINIBIDIR 
PRIY[TITISILI via lo}—| 
NUS [RIP Ir l—|TILIx| 
PPIWITIS(RI- [Ui Liniy| 
PCIL[E(E(DIAIT IA JAIN] 
PETRUN ITAA JODIE IS) 
GUSTO TI - Ic [RIE TE IT] 
MITIRIPIOVEITIF I~ [UI 


Figure 9-17 (C). Reconstructed matriz (U). 


BWOAWN AAA WHHL 


By manipulating the rows and columns, a diagonal 
arrangement of the plaintext values can be obtained 
as shown in figure 9-18. 


68691543729 


lalalalc[o[e{e| zr] fr 
afalc(olef ela txta [0] 
ate (ole (ele [o[uToTR 
CB) le 
cfefeo(t|wfotais |r| 
ElElriT Tao lQ[s[ rir 
ele tpsfo[P (Ry rl rie 
iti. pilPlRis frye pc 
ric py le [R/S [a fupwy | 
elepopRispe(t Tye [e) 


Figure 9~18 (C). Recovered matriz (U’). 


NO HoH WHY 


Section IV. ro MULTINOMIC SYSTEMS 


9-13. General 

a. Analytically, any distinction between multi- 
literal and multinomic systems, because of the use 
of alphabetic or numeric values as row and column 
indicators, is generally inappropriate. Multiliteral 
systems of the type previously covered employ the 
same principles of cryptography, independent of the 
nature of their row and column indicators. Thus, 
being cryptographically similar, they are susceptible 
to the same analytical techniques of their identifica- 
tion, analysis, and final solution. 

b. There are several systems, though multiliteral 
with variants, which are sufficiently different to 
warrant additional study. These systems use numeric 
values exclusively for the cipher elements, and the 
manner of deriving the cipher element is somewhat 
different from that normally associated with multi- 
literal systems. The systems can be classified as 


A BCDEPFcGHIy K LM 


Key: TRHP 


Gs [O20 [2 [ne [as] a4 es 26 |i? [1a 49 [Bo [er [2 Bs [ea [2507 [oa] 03 4 [Os [ow TI 
35 [36] 37/38 [39 [40] 47 [42 |43 | 44 [45 | 46 [47/48 [49 | 50 [26 [27] 28 |29| 30 [37 [52] 33] 34! 
69 |70|71| 72] 273 |74| 75 151152135 ]54| 55 [56|57[58|59 [60 [67] 62 |63| 64 [65 [66 [67/63 
(87 [88[ 89] 90|91] 92/93 |94 195] 96 | 97] 98 [29] 00|76| 77 [78179] 80 181) 82 183 [84 [85 8c 


multinomics, and the techniques of analysis employed 
are slightly different. 

c. Cryptographic systems which may be grouped 
within this class are the columnar numerical, the 
monome-dinome, and the monome-dinome-trinome 
systems. 


9-14, (D Colonia Numeric System 


a. One of the most simple of the dinomic systems 
from both a cryptographic and a cryptanalytic point 
of view is a columnar numeric system. This is a 
multiliteral system because the cipher element to plain 
element ratio is commonly 2 to 1, but it is unlike 
the previous systems because the cipher element is 


not derived from row and column coordinates. 
Each plaintext value is assigned several cipher 
values arranged in a columnar matrix as depicted 


in figure 9-19. 


RS 7 UV WwW xX 2% 


Figure 9-19 ve Columnar numeric system (U). 


» 


9-16 CONFIDENTFAL- 


b. The number of rows of dinomic cipher values 
may vary as may the system of inscription. Note 
that in the above example, each row of 26 sequential 
letters begins at a letter corresponding to a letter 
of the keyword and is inscribed in its normal pro- 
gressive order. The overall security of the system is 
easily improved by randomly assigning the dinomes 
in each row. However, this entails the loss of its 


A I R REcowNwWNaAISsSs S ANCE Tr. NDT 
24 12 10 48 47 56 35 43 27 61 87 4T 37 12 


08 16 26 

Es ENE 

73 27 91 99 39 4 
ARE BEING 
35 26 39 «©6970 73 95 56 75 


BAN KO 
36 08 99 4b 48 7 


NO 
U7 57 


Oo T H ER IN 
21 28 h2 73 60 


E WN E M Y W 


M Y AR ? Tb LD E R Y 
6 85 69 60 62 52 45 54 39 60 67 


F S$ 0 U T H 
4 61 21 29 80 15 


IT HDRAWA SL 
39 56 12 98 33. Ob 43 62 51 11 60 87 31 08 45 


primary advantages which are a limited number of 
dinomic strips, each sequential and juxtaposed on 
a keyword that is easy to remember and duplicate. 

c. A message is enciphered by substituting for 
each plaintext value one of its dinomic cipher 
equivalents. For example, a message can be en- 
ciphered with this system as shown in figure 9-20. 
Decipherment is just the reversal of encipherment. 


Cc A T: 
52 56 38 52 71 69 28 


U N ITs 
29 56 16 O1 25 


Dvd, 6: (Ps LA. Ce DY) OO. SP Ad AR 
72 43 61 58 45 87 71 39 72 


28 57 


R IV ER S T 0 P 
60 16 64 12 60 27 62 8 22 


DI¢<c A Tf O RFR S Ovo 
95 47 38 52 10 35 62 21 24 79 


OBS ERV ED X 
21 36 27 39 60 03 73 90 66 


08162 62412 10484 75635 43276 18747 37125 25638 
52716 92873 27919 93946 85696 06252 45543 96067 
29561 60125 35263 97073 95567 57243 61584 58771 
39722 85792 35263 60899 44487 46121 29801 56016 
64126 02762 48224 75721 28427 36095 47385 21035 
62212 47957 40395 61298 33044 36251 11608 73108 
45213 62739 60037 39066 


Figure 9-20 (C). Encipherment using the columnar numeric system (U). 


d. Analysis generally involves the same techniques 
as the analysis of uniliteral monoalphabetic ciphers, 
with provision made for the fact that a number of 
dinomic sequences are involved. Assuming that the 
dinomes of the system have been inscribed sequen- 


tially, a four-part dinomic frequency distribution can 
be made with each part corresponding to 25 or 26 
progression numbers. For example, such a frequency 
distribution of the message above would appear as 
in figure 9-21. 


“CONFIDENTIAL — +17 


468-095 O- 72-9 


& Ill 


09 


wr Ill 


32 34 


— 
= 


ot 


OQ ttt Il 


55 56 29 


76 80 81 82 83 Bk 85 87 


63 


88 


19 


Fill 


50 


a | 
(oe) 
me | 


6.6566 


89 90 91 92 93 94 95 96 97 00 


Figure 9-21 (U). Four-part dinomic frequency distribution (U). 


e. Each sequence above represents a simple mono- 
alphabetic frequency distribution. This fact, once 
realized, should immediately lead to the next step of 
fitting the distribution to the normal. Note that the 
second and third sequences have the most pro- 
nounced peaks and troughs, and therefore would be 
the sequences to begin with. Once they have been 
fitted to the norm, the remaining sequences fall into 
place as each sequence represents a part of a whole. 


ABCDEFGHIWUWUKLM 


Without referring back to the original cryptographic 
system, the analyst should be able to equate three 
of these sequences to the norm by visual inspection 
alone. For example, starting with the third sequence 
and mentally matching an alphabetic sequence to the 
peaks and troughs, it is clear that 5/c= Hp. The same 
type examination of the second sequence shows that 
35c= Ap. These two may be inscribed thusly: 


NOPQRSTUVWXYZ 


35 36 3% 88 39 40 41 42 48 44 45 46 47 48 49 50 26 27 28 29 30 31 32 83 34 


69 70 71 72 78 74 75 51 58 53 54 65 


f. The placement of the first and fourth sequences 
would be a little more difficult under ordinary circum- 
stances. However, this is not necessary. The sequence 
recovered represents 50 percent of the total system; 
therefore, one-half the text could be recovered, thus 
permitting the assumption of plaintext values for the 
cipher dinomes of the two remaining strips. Moreover, 
since each sequence is progressive, the valid assump- 
tion of only one cipher value inevitably leads to the 
placement of all others. 


9-15. (Z) Monome-Dinome Systems 
a. This type system, one of the more important 


56 57 58 59 60 61 62 63 64 65 66 67 68 


multiliteral systems, differs from others in that it 
replaces constant-length plaintext units with cipher 
elements of variable lengths. The ratios of cipher 
element to plain element may be 1 to | or 2 to I. 
The variation in the ratio is brought about by 
omitting one row coordinate. Thus, some plaintext 
letters are represented by a two-digit cipher element, 
composed of both row and column indicators, while 
others are indicated by a column indicator only. 
Figure 9-22 illustrates the structure of the system, 


and its application in enciphering a message. 


L234 5 GT 8 Oe 


4 [alilaleltci[3{[pi4lels} 

6 [Flé[o{7le{léiiiylsi¢| 

; IK{.{uL[-[M|[-[u[-]0| P| 
MOVE R ES ERVE BATTALION 
5 9 86 49 82 49 83 49 82 386 4g 43 41 84 84 41 367 9 7 
T Oo BLoOc K IN G Pos IT TON 
849 433 9 45 «167 ~«T «63 G 9 83 67 646 67 G 7 


Figure 9~22 f. Monome-dinome system (U). 


9-18 


GONFIDENTIAL 


CONFIDENTIAL — 


Note that in the matrix, blanks appear where the | ) 10 i5 20 25 
blank row intersects columns having as coordinates 
a value used as row indicators. Thus a blank appears 
in columns 4, 6, and 8 above (as 4, 6, and 8 were 
used as row indicators) to preclude confusion in 
decipherment. For example, if a value (A) did 
appear at the intersection of a blank row and 
column 4, its value would be 4. Since 44c also 
represents 2p, the deciphering clerk would have to 
decide which was the correct value, two A’s or the 
digit 2. 

b. Examination of the ciphertext produced above 
reveals two important facts. First, there is a constant 
relationship between cipher and plaintext values 
with no variants. Thus, Ep is always equal to 49¢. 
Second, the use of monomics does nothing more than 
confuse identification of this constant relationship. 
For example, the text above divided into 5-figure 
groups would appear thusly: 


59864 98249 83498 28649 48418 48441 36797 
* 84943 39451 67763 09886 78467 97 


On the surface, the text shows no evidence of which 
dinome or monome represents what plaintext value, 
as the individual identities of the dinomes and 
monomes are lost in the formation of the ciphertext. Figure 9-23 (C). Ciphertext and monomic frequency distribu- 
Moreover, because there is a constant relationship tion (U). 

between a given dinome or monome and a plaintext 
value, it follows that solution of this system lies 
first in isolating the monomes from the dinomes 
and then in identifying each. Thereafter, a solution 


742381 09202 85723 27201 68955 
76762 35820 73555 82873 17676 
00072 47757 =73778 = 87915 87272 
23782 38778 56692 38777? 85895 
07707 78789 77878 29788 23229 
00997 79125 808235 81581 97758 
207385 08823 73775 81991 22567 
85007 01199 17650 77577 = 89882 
80724 97450 


HOODY QW 


Monome Frequency Distribution 


Pa ee 


a ee ee i ee ee ae 
POW i= 

WA ERP OAM FOP 

cred eS ee ey ED 


So oORAANV EWN EH 


(1) The disparity between the frequencies of 
each digit in the monomic distribution is obvious 
and indicates that 2, 5, and 7 probably represent 


aceaney 1 Ftiai h - row coordinates. If this is correct, a matrix similar 
is primarily a matter of reducing the text to unilitera to the following can be drawn up containing a blank 


terms and solving it accordingly. row with blank cells beneath the column indicators 
c. Identification of a monome-dinome system is 2,5, and 7 


based on the following characteristics: 
(1) The length of the cryptogram may be 
either odd or even. 


(2) Repeats are consistent in length and struc- 
ture within a message and may or may not be | 
divisible by a constant factor. 2 on 

(3) Interval between repeats may or may not | 
be divisible by a constant factor. 


frequency distribution in figure 9-23, the above an 
characteristics may be noted. 


(4) A monomic frequency distribution may 6 | | 
reveal two or three digits with a high frequency. (ise nets ete es 
d. Considering the message and its monomic y | | one 
! hoes 

i 


CONFIDENFHAL— 9-19 


CONFIDENTIAL 


(2) Using the cipher elements that can be 
derived from this matrix, the cryptogram can now 
be rendered to its correct elemental construction 
as depicted below: 

74~23-1-59-20-23-57-283-27-20-1-58-9-66-76-76 

23-58 -20-73-55-68-23-73-1-76-76-55-57-24~77-57-73-77 

58-79-1~-88-7 2-7 2-23-77 3-23-57 -78-55-59-~23-8—-77-78-88 

9-56-77-57-78-78-9-77-8-7 8-29-17 8-8-23-22-9-56-9-9-77 

§1-23-8-68-23-8-1-68-1-9~77-658-20—-73-66- 58- 23-73-77 

58-1-9-9-1-22-56~78-56-57-51-1-9-9-1-76-56-77-57 

78-9-68~23-57-24-9-7 4-50 

(3) From this point on, if monomes and dinomes 
have been identified correctly, the solution is 
essentially the same as that used for uniliteral 
monoalphabetic ciphers, as a direct relationship 
exists between one plaintext element and one cipher- 
text element, regardless of the latter’s configuration. 
As a matrix is involved, the analyst has an additional 
advantage. As the plain values are recovered, they 
may be inserted into the matrix. Assuming that a 
systematic method of inscription is followed with 
a normal alphabetic sequence, the route often can 
be assumed, permitting the placement of all values. 
These must later be proved by actual decipherment 
of the cryptogram. 

e. A facet of both above matrices is the marked 
difference in the number of rows and columns; in 
both, the ratio is 4 to 10. This made possible the 
distinction between row and column indicators 
through the use of a monomic frequency distribution. 
Were the matrix to have an equal number of rows and 
columns, for example 6 each, it would produce a 
generally flatter frequency distribution. The occur- 
rence of digits with any great frequency would be 
due to the encipherment of high-frequency letters 
rather than the repeated use of a few row coordinates. 
Thus, the identification of a monome-dinome system 
is more difficult. In such cases, identification some- 
times can be based upon the internal characteristic 
of the text. For example, consider figure 9-24 con- 
taining a message produced by this type cipher and 
its monomic frequency distribution. 


9-20 CONFIDENTIAL 


5 10 15 20 25 
A 57357 89418 28464 71715 82946 
B 16482 88257 57482 64549 16436 
C 47364 84946 36471 71616 49159 
D §6827 45646 26384 


Monome Frequency Distribution 


Ste &@N YD HAW Ob 
ON NN 
AMM RH ru ©. 

NE ae eee 


Figure 9-24 ri Cipher message and monomic frequency 
distribution (U). 


(1) Upon initial examination, the cryptogram 
appears to be digraphic. The primary clues that it is 
not are the absence of the zero in the distribution, 
and the fact that the repeated groups, although even 
digits in length, lie at uneven distances from the 
beginning and end of the message and from each 
other. With nine digits as row and column coordi- 
nates, there could only be a matrix of 20 cells with 
4 rows x 5 columns or reverse, unless one blank row 
indicator is used. A blank row indicator would pro- 
vide for a 5 x 5 matrix of 25 cells which is suitable 
for an alphabet when assuming the I and J, or U 
and V are combined. It is possible to repeat a digit 
as both row and column indicators, but this would 
be reflected in the frequency distribution by that 
digit occurring more often. Also the 9 probably would 
have been used first before one of the other digits 
were repeated. 


-GONFIDENFIAL— 


(2) Having tentatively identified the system, the 
analyst may now attempt the recovery of the matrix 
coordinates. The approach in this case, assuming no 
like-digits were used as row and column indicators, 
is to locate all doublets. Repeated digits, assuming 
the limitation above, are probably the repeated 
occurrence of a dinome derived from the intersection 
of a blank row and a numbered column. Searching 
the text, the doublet 55 is noted. Thus, on the basis 
of the reasoning above, 5 is accepted as a possible 
column indicator (fig. 9-25). 


Figure 9-26 (U). Initial placement on column indicator (U). 


(3) A 9 is noted as immediately preceding the 
doublet 55, which is also preceded by a J. If 5 is 
indeed a column indicator the correct spacing of the 
cipher sequence must be 5 95 5. Thus 9 can be 
tentatively accepted as a row indicator. If so, then 
9 will appear only in conjunction with other digits 
which are column indicators. Searching the text, 
the dinomes 91 and 94 are found; thus J and 4 can 
also be accepted as column indicators. The process 
results in the expansion of the matrix as shown in 
figure 9-26. 


Figure 9-26 (U). Expansion of matriz (U). 


(4) Searching the text again for further pat- 
terns, the first group 57357 is noted. As 4 is accepted 
as a column coordinate, the 7 which follows the 4 
above must be a row indicator. Thus 73 is a dinome 
row and a dinome column indicator respectively. 
Again, a search is made for combinations of 7, and 
73, 72, 71, 75, and 74 are found. The assumed can 
now be inscribed (fig. 9-27). 


Figure 9-27 (U). Second expansion of row and column indt- 
cators (U). 


(5) By a continued inspection of the text, 
working backwards, i.e. finding a digit which pre- 
cedes an assumed column indicator, all row indica+ 
tors can be isolated quickly producing a matrix 
similar to that shown in figure 9-28. 


Figure 9-28 (U). Final reconstructed form (U), 


With this matrix, the cryptogram can be fractured 
to its individual cipher elements, reduced to uni- 
literal terms, and solved by a method similar to 
that of the preceding example. 


9-16. (Z) Monome-Dinome-Trinome System 


a. A ‘monome-dinome-trinome system is essen- 
tially the same as a monome-dinome system with, 
as the name implies, a trinomic element. This ele- 
ment is included as shown in the matrix and crypto- | 
gram in figure 9-29. 


GONFIDENTIAL— 9-21 


CONFIDENTIAL 


12345678949 
PAIFIGIL|-[QlRiw]-[- 
LBiEtuIKIMIPis[vixt I 
Lcipitisinjolrivtyiz! 


E N EM Y A T TA C K I NG Z@ 
02 905 52 55 909 1 907 907 1 901 54 903 905 3 900 


90 


52905 62559 09190 79071 90154 90390 53900 
Figure 9-29 te Ezample of monome-dinome-trinome system (U). 


b. The solution of this system is basically the same 
as that for the first preceding example of a monome- 
dinome system. Identification, again, is usually made 
through the use of a monomic frequency distribution 
which will reflect a high frequency of use for those 
digits used as row indicators. Normally, an examina- 
tion of the text will reveal two of these high-frequency 
digits combined in most cases in the cryptographic 
text. Once the row and column indicators have been 
isolated, solution again is merely a matter of fraction- 
ing the text into its component cipher elements, 
reduction to uniliteral terms, and establishing the 
plain-to-cipher values. As an aid, the matrix can be 
reconstructed simultaneously. 


9-17. (Z) Trinomic System 
a. A variant form of the basic multiliteral system 


1 
a | 


16 


72 


38 


94 


50 


16116 45011 61383 


16316 53423 84385 


is the trinomic system in which a constant length 
cipher element of three digits replaces a constant 
length plaintext element, usually of one letter. 
Structurally, the systems are similar in that both 
employ a matrix with row and column coordinates 
and an alphabet inscribed therein. The primary 
difference is that in the trinomic system one set of 
indicators is dinomic and the other is monomic. The 
dinotnic element may appear either as row or column 
indicators usually limited to one position, but it is 
possible to mix them between the two. Further, it is 
possible to use alphabetic values in this system rather 
than numeric values. An example of the normal con- 
figuration of the system using numeric values is 
shown in figure 9-30. 


28 4 6 
pfefole 
cfs [a fol | 
etn] fof | 
jeje |s |e al 
AAA 


A Db V A N C E T O 
161 164 501 161 383 163 165 942 384 385 723 161 943 165 


P H A SS. E L fT NE 
381 722 383 165 


7238161 943816 58817 22383 165 


Figure 9-30 Jf . Trinomic system (U). 


b. Cryptographically, the system offers little. As 
can be seen in the encipherment above, there is still 
the one-to-one relationship between the plain and the 
cipher element. In effect, the system only increases a 
message length by threefold with little increase in 
security. 

c. Recognition of a trinomic system is possible 
through its basic characteristics. They are: 


(1) Message length, discounting nulls, is divisible 
by three. 

(2) Repeats are divisible by three. 

(3) Intervals between repeats are divisible by 
three. 

(4) Positional limitation of the dinome and 
monome indicators make up the trinome. 


9-22 GONFIDENTFIAL— 


~ 


GONFIDENTIAL 


(5) Little frequency deviation is shown on a 
monomic frequency distribution. 

d. An analysis of the characteristic above usually 
suffices to identify a trinomic system and to separate 
it into its component cipher elements. For example, 
observe the message below. 


56712 79059 05125 78990 57853 


48565 84766 11257 85567 90178 
156738 47785 90578 18431 29901 
78734 75671 27905 90512 53439 


01567 56734 77859 00000 


(1) Each repeat, each interval between repeats, 
each interval between repeats and end of message, 
and the overall message length except for three 
zeros used as nulls, is evenly divisible by three. 
Further, a close study of the group reveals the 
trinomic grouping. For example, the first two lines 
of text can be divided as follows: 


567 127 905 905 125 789 905 785 343 
565 84% 561 125 785 567 901 781 567 
B47 785 905 781 348 129 901 787 347 
567 127 905 905 125 348 901 S567 567 
847 785 900 000 


(2) Having reduced the ciphertext to its ele- 
mental parts, the matrix now can be recovered. 
This is a simple task due to the positional limitation 
inherent to the system. Note each of the trinomes 


listed above. A close study reveals that each is 
composed of two units: a dinome and a monome. 
Further study also shows that the dinome is limited 


to 12, 34, 56, 78, and 90, and the monome to 7, 3, 


5, 7, and 9 respectively. Using these values a matrix 
can be reconstructed as in figure 9-31. 


90 
Figure 9-31 (U). Reconstructed matrix (CC). 


(3) With the ciphertext in its elemental parts, 
where the one-to-one ratio exists and with the 
matrix defined, solution of the message is rapid. 
It would be studied and analyzed exactly as a 
uniliteral monoalphabetic substitution cipher using 
all techniques associated with the solution of that 
type system. : 


CONFIDENTIAL— a 


CONFIDENTIAL 


PART FOUR oh 
POLYGRAPHIC SUBSTITUTION SYSTEMS 


CHAPTER 10 g 
CHARACTERISTICS OF POLYGRAPHIC SUBSTITUTION SYSTEMS 


10-1. (ZB General 

a. The substitution systems dealt with thus far, 
with the exception of the syllabary square and code 
charts, have involved plaintext units of single ele- 
ments. This part deals with substitution systems 
involving plaintext units composed of more than 
one letter, such systems being termed polygraphic. 
Perhaps the reader has noticed the distinction be- 
tween the use of the suffix “literal” and “graphic.’’ 
Terms involving literal refer to the composition of 
the ciphertext, as in multiliteral systems; terms 
involving graphic refer to the composition of the 
plaintext elements treated. Within this broad classi- 
fication there are distinct systems classified by the 
number of plaintext elements involved in the en- 
cipherment process, the most common of these being 
the digraphic system, which involves a double 
element cipher unit. 

b. A major characteristic of the digraphic system 
is that both the cipher and the plaintext elements 
are composed of two units, and the two units of the 
latter jointly determine the composition of the cipher 
element. In these systems, since the plaintext units 
jointly determine the composition of cipher elements, 
it cannot be said that any single plaintext letter has 
any one particular cipher equivalent. For example, 
in certain digraphic systems ABp can be enciphered 
as XPe while ACp becomes NRc. Thus the change 
in identity of but one of the plaintext letters acts 
to change the identity of both letters of the cipher 
digraph. The method by which this change is brought 
about will be explained in detail in subsequent 
paragraphs. This joint characteristic of determina- 
tion is indicated by overscoring the digraphs in- 
volved, thus XPc=ACp. 

ce. The primary purpose of polygraphic systems is 
to provide a means of eliminating, or at least sup- 
pressing, the frequency characteristic of plaintext 
letters. In the preceding cipher system, the impor- 


Section I. 9) CHARACTERISTICS OF POLYGRAPHIC ENCIPHERMENT 


tance of this phenomenon as an “in” to the analyst 
is amply demonstrated. In the case of uniliteral 
monoalphabetic substitution where a direct one-to- 
one ratio is obtained, it was shown that it could be 
solved quickly by a simple tabulation, applying 
the principles of frequency and laws of probability. 
So it was too in the case of multiliteral substitution 
systems, where several, though constant, cipher 
values could be reduced to uniliteral terms. The 
important point here is that security is not neces- 
sarily a factor of the ratio of cipher element to a 
plain element, nor to the complexity of the system, 
but to the total number of variations for each pos- 
sible value of the system as a whole. 

d. In polygraphic substitution, variations are 
introduced into the system through both the cipher 
and the plain components. The fact that encipher- 
ment can be accomplished by combining letters 
serves to decrease drastically the opportunity for 
application of the laws of probability and principles 
of frequency. For example, in a message of 100 


characters enciphered by a uniliteral monoalpha- 
betic substitution system, there are only 26 different 
possible letters that require identification. In oa 


digraphic system based upon an alphabet of 26 
letters, there are 676 possible combinations, and a 
message of the same length in a digraphic system 
would only represent 50, at the very most, of these 
possible combinations. Thus the laws of probability 
and frequency characteristics have a restricted 
range in which to operate. 


10-2. (Z) Polygraphic Substitution Using Tables 

a. The simplest method of polygraphic substitu- 
tion involves the use of a table similar to that 
shown in figure 10-1. The operation of the system 
is based upon row and column coordinates us the 
plaintext values, which are replaced by the cipher 


value found at their intersection. Thus AG» becomes 


—CONFIDENTIAL— 10-1 


F Bc. In those cases where a single letter occurs, as 
for example at the end of a message, encipherment 
as a digraph is obtained by adding a null, preferably 
a high-frequency letter. Words are enciphered by 
dividing the word into digraphic elements, then 
using the plain digraphs as row and column co- 
ordinates to locate the equivalent cipher digraph. 
For example: 


DEFACED 
X DE FA CE D 
YA NZ CY 
P2 
A BC D_E F GH I J K 
we 
[wy|pc|valzi{xxtox| | | | ty: - 


XX 
» [eal os} FH] 


cl || at [| [al [TT]: - - 
pt t_les| lal || [yt]: -- 
A ee ee 
eo FL_bol | iz] | fazt [ [d- - - | 
(Pe TeLLCLCLiEIcCi-::-: Cher 
xCUTCL ELL lal): - : elo 
yjoel | |_| [ltt]: -- Ceo 
zfael LLL LLL ler TI; Cex 


Figure 10-1 (C). Reciprocal cipher table (U). 


A BC ODEF GH I éJd 
GC HT OI VO 
HC OT UI AO 
RO 
BO 
KO 


co 


EE SN TR 
IN IR 
IN NR 
NN GR 
GN HR 
HN OR 
UR 


IA 
NA 


MM 
PM 
Qi 
Vil 
Aid 
YM 
VA 
Wi 
EM 
SH 
TM 
Il 
NM GP 
Gld HP 


BBB 


NHMESCHHNDOVOR ES MrAUVHROQDMAOANe pe 


Figure 10-2 ( 


10-2 


M 


AY 
OY 


HlMf OP UY AB 
Ol UP AY RB 
UM AP RY BB 


[AL 


b. The analyst may have noted that the cipher 
in figure 10-1 is reciprocal, ie. AGp=FBe and 
FBe=AGp. This particular cipher is deliberately 
constructed in this manner for ease of use, being 
capable of use in both the enciphering and the 
deciphering process. Reciprocity is not an essential 
factor, and for purposes of security is usually 
avoided. The overall security of the system above, 
where only one cipher equivalent is available for 
each plaintext digraph, is directly dependent upon 
its use. The security of a eryptogram produced 
through its use is relatively good until such time as 
its overuse permits the isolation and identification 
of the more frequently used digraphs. 

c. A similar system is illustrated in figure 10-2. 
Encipherment of plaintext values is again by the 
use of row and column coordinates. Thus ABp 
becomes HEc. Note, however, in this case the values 


are nonreciprocal, i.e. EEp=OAc rather than ABe. 
To decipher a message, the cryptographer looks 
outward from the cipher digraph to row and column 
coordinates, thus locating its equivalent plaintext 
digraph. 

N 0 P QRS T U V W 
JJ LK MQ PS QU 
LJ WK PQ QS VU 
HJ PK QQ VS" 
PJ QK VQ XS 
QJ VK XQ YS 
VI XK YQ ZS 
XJ YK Z2Q@ WS 
YJ ZK WQ ES 
ZJ WK EQ SS 
WI EK SQ TS 
SK TQ IS 
TK NS 
GS 


DF FR 


PV 
LQ MS PU QV VW 


. Nonreciprocal cipher table (U). 


‘CONFIDENTIAL 


CONFIDENTIAL 


d. Although the table above is nonreciprocal, a 
close examination reveals a certain symmetry of 
values in the inscription of the cipher elements. The 
result is that, unlike the former table, the encipher- 
ment is not truly digraphic in character. Note that 
in the case where the second digit of the plain digraph 
remains constant, the second digit of the cipher 
digraph_als also remains constant. Thus AAp= WGe, 
BAp=£EGe, CAp= SGe, ete.; ; AAp= WGc, ABp=EEc 
and ACp=SNe. The total result i is that the encipher- 
ment cf the first character of the digraph is always 
polyalphabetic, while the encipherment of the last 
character of the digraphs is monoalphabetic in 
vertical encipherment. 

e. Generally, digraphic substitution using tables 
such as those previously illustrated are impractical 
for military use. This is not due primarily to their 
security faults, as this can be corrected, but because 
of their physival limitations. The relatively large size 
of the tables, the inconvenience of their production, 
change, distribution, and handling make their use 
impractical. Moreover, the same, or better crypto- 
graphic results can be obtained by the use of matrices. 


10-3. (¢ 


Polygraphic Substitution Using Mat- 
rices 
a, A simple method for obtaining digraphic sub- 


stitution is through the use of a four-square matrix.. 


This is a matrix which contains four components, 
two cipher and two plain, each inscribed in a 5 x 5 
square. The components are 25-letter alphabets in 
which two letters are combined, normally the I and 
the J (only the I being shown), and inscribed in the 
square by some predetermined order. Figure 10-3 
depicts a normal four-square matrix. 


f4lalclo| zl rlolul riz 
LF iG] ali] K] | m| Plot el 
pi | £|m| lol pl xy z{s|yI 
polr{s| riot x| wv] | 
viw| xt yi ztale| [cla 
Tia |i xe Al al cl ol el 
lolrlols|yi rel alia x 
jul y| zo] lz} mM] yj ol P| 
i {x|w|v| alot s| zi vl 
Kiel Fjotc| yim x} y] z| 


Figure 10-3 (p. Four-square matriz (U). 


C1 


C2 P2 


(1) Digraphic encipherment is accomplished by 
locating the first character of the plain digraph in 


section P1 and the second in section P2. The substi- 
tution cipher values are found in section C1 and C2 
respectively at the opposite corners of an imaginary 
Square or rectangle. Thus ZAp becomes HE. This 
is demonstrated in figure 10-4@. 


Figure 10-4@ (). Enciphering operation, four-square 
matriz (U). 


(2) Decipherment is exactly the reverse of the 
enciphering process as shown in figure 10-4@). The 
units of the cipher digraphs are located in section 
C1 and C2 respectively, and their equivalent plain- 
text values are found at the intersection of an 
imaginary square or rectangle in section Pl and P2. 
For example XEc= UBp. 


Plp ttt teat cr 


PEE ERME Eee 
p= |-{-[y | Zit f7t cl | 1 - | 


eg 


Figure 10-4@ VA Deciphering operation four-square 


matriz (U). 


(3) Note that with each successive plain-cipher 
digraphic relationship, a new enciphering rectangle 
is created and outlined. Thus, what was previously 
mentioned as the ideal of polygraphic substitution 
now occurs. No individual letter by itself has any 
attached specific value. Rather its value only occurs 
as a result of its combination with another letter, 
and for each combination, different values result. 
Thus in figure 10-4@) AFp=F0c, AHp=U0e, and 
FHp=P0c. 

b. It is possible to effect the same type of en- 
cipherment by using a two-square matrix and a 
modification in the method of finding equivalents. 
One such two-square arrangement, a horizontal 
two-square, is illustrated in figure 10-5. 


- ~GONFIDENTIAL — 10-3 


MTANIUIF | Alu riots 
clneuie Pairiziets 

[Die lAlK | clDlFiGla| 
ZlolPiais | xiv [Pl@lR| 
[viwix[y[z | viwixtyiz! 


Pe 
Cl 


Figure 10-5 re Horizontal two-square matrix (U). 


Basically the method of encipherment is identical 
with that of the four-square method, the equivalent 
cipher values for P1 and P2 being found at the oppo- 
site corners of an imaginary rectangle in section 
C1 and C2 respectively. Thus MPp=TLe. The 
exception to this rule is when the two plaintext 
letters appear on the same horizontal row. In these 
cases, the cipher digraph produced is a reversal of 
the plaintext digraphs. Fe For example, the cipher 
equivalent for TEp is ETe. Observe that in both 
cases the first cipher letter is in the same column as 
the second plaintext letter. 

c. Digraphic substitution of the same sort may 
also be effected by the use of a vertical two-square 
matrix as illustrated in figure 10-6. 


Figure 10-6 (€). Vertical two-square matriz (U). 


(1) The principle of encipherment and deciph- 
erment is once again the same as in the preceding 
example..The ciphertext values are found at the 
opposite corners of an imaginary rectangle, deline- 
ated by the position of the first and second digits of 
the plaintext digraphs. For example MOp becomes 
UAce. In this matrix where the two plaintext letters 
are found in the same column, the cipher digraphs 
are identical. Thus MAp becomes Mac. Note that 
unlike the horizontal two-square, the cipher equiva- 
lent is not a reversal of the same letter but the same 
letters in the same sequence as the plaintext. 

(2) -In both the vertical and the horizontal 
two-square systems shown above, the encipherment 
of a single letter can be accomplished only by adding 


a null to form a plaintext digraph. Usually, for 
reasons of security, the null chosen is a high-fre~ 
quency letter. 

d. A third method of digraphic encipherment 
using matrices is the Playfair cipher which involves 
only the use of one 5 x 5 square. The use of a single 
matrix is possible by yet another modification of 
the system of finding cipher equivalents, which 
results in a greater degree of security. A typical 
Playfair cipher is illustrated below: 


AQ@PON 


dab 
ND 
GN 
Say 
AOS 


EFGaHHI 


Encipherment and decipherment are considered in 
light of four categories of plaintext placement. 

(1) When the members of the plaintext pair 
are at the opposite ends of a diagonal of an imaginary 
rectangle, the replacement cipher members are at 
the opposite ends of the other diagonal. Thus 
AHp=0OEc. Note that cipher 1 always is selected 
from the same row in which plain 1 appears: thus 
ZEp=CGe, and BZp=YCe. 

(2) When the members of the plaintext pair 
lie in the same row, the letters immediately to their 
right form the cipher pair. Thus APp=Q0Oc, 
POp=ONe, and ONp=Nace. 

(3) When the members of the plaintext pair 
lie in the same column, the letters immediately 
below them form the cipher pairs. Thus ADp=BEc. 
CEp=DaAe, and EBp=ACe. In both this case and 
that above, the rows and columns form continuous 
circles. 

(4) When the members of the plaintext pairs 
are repeated letters, they must be separated by 
inserting a null, in this case usually a low-frequency 
letter such as Q or X, and then be enciphered by one 
of the three methods above. For example, the word 
BATTLES is enciphered as: 


BA TQ TL ES 
CB FR KS FC 


A Playfair square is automatically reciprocal so 
far as encipherment by method (1) above is con- 
cerned. Thus Atp=PBe, and PBp=Ye. This 
reciprocity does not occur in method (2) and (3) 
above. Decipherment takes the exact reverse pattern 
of those methods outlined for encipherment. 


10-4. ( 


Variant Forms of Polygraphic Enci- 
pherment 

a. In the foregoing paragraphs, polygraphic en- 
cipherment is totally limited to its digraphic forms 
for which table and matrices are used. It is important 


10-4 GONFIDENTIAL- 


GONFIDENTIAL 


that the same basic system is so constructed as to 
provide trigraphic and tetragraphic encipherment 
and even combinations of these. In effect, the systems 
operate on the same general cryptographic principles 
with some variation to fit the specific case. 

b. One possible variation of a Playfair square is 
shown below. This illustrates that matrices need 
not always be square, though this is the most 
common form. 


Ww A S H I N 
G T O B C€C D 
E F J KA KE KI 
KO KU L M P @Q 
Boo Vo Ox Oe 


c. Encipherment of a message by the system 
results in the introduction of an occasional trigraph 
or tetragraph in addition to the normally expected 
digraphs. Thus AMp=HKUc and EPp=KEKOc. 
Also a number of variant values may be introduced, 
as CKp could equally be represented by BKEc, 

"KEPc, DKEc, GPc, and TPe. Insofar as deciphering 
the possible variants shown above, the deciphering 
clerk would merely ignore any letters following the 
K when obtained in the process of decipherment. 
Thus CKOp would be read as CK. 

d. A numeric variation of the four-square system 
shown earlier which permits a trinomic substitution 
of digraphic plaintext elements is illustrated in 
figure 10-7. 


patetct ote | [00 [025 | 050 | 076 | 200 | 

Par Pies Tirso [7s | 200 Pegs | 

Pera rae bas ts tape aa Dae 

Pin tao tees | a50 | a5" 

pepetete te foo ee sober Lene] 
eons sameness some ——= 


PL Cl 


A 3 ee = 
nates ie fet et nt ee P2 
ae a a 
p20 P21 f2e jes Jee Tz uy ey ey] 


C2 


Figure 10-7 (C). Numeric variation, four-square matrix (U). 


(1) Encipherment of a message proceeds as 
normal for a four-square system, but the numeric 
values are added rather than used as tetranomes or 


pentanomes. 
PR OC EE DI NG 
275 350 100 075 325 
9 13.24 18 7 
284 363 124 093 332 


(2) Decipherment is accomplished by deter- 
mining the greatest multiple of 25 contained in a 
given trigraph and then subtracting that multiple 
from the trigraph to derive Cl and C2. 


284=275 284=275+9 275e—9c=PRp 


e. The clumsiness of the two preceding systems 
explains why they are not often encountered in actual 
operations. As stated previously, one of the impor- 
tant requirements of a cryptographic system is that 
it be practical for common usage. While the systems 
do provide a degree of extra security, the amount 
gained is hardly worth the effort. 


Section Il. (C) RECOGNITION AND IDENTIFICATION OF POLYGRAPHIC SUBSTITUTION 


10-5. (J) Recognition of Polygraphic Substitu- 
tion 

a. The methods of determining whether a given 
message represents a case of polygraphic substitu- 
tion are rather simple. Usually a close inspection of 
certain of its physical characteristics suffices. When 
the techniques do not give clear-cut answers or 
when the lack of volume of text to study makes its 
use inappropriate, the analyst still has recourse to 
statistical tests and identification tables. 

b. Digraphic substitution systems generally ex- 
hibit one or more of the following characteristics. 

(1) Excluding nulls and indicators, message 

length, textual repeats, and internal distances will 
be multiplies of two. 


(2) When the ciphertext is composed entirely 
of letters, all are present, except one, usually the J, 
the U, or the V. 

(3) If the ciphertext is composed of numbers 
when divided into trinomes, a limitation of range 
occurs, usually 001-676. 

(4) Repeats usually begin on the odd letters 
and end on the even letters. 

(5) The cryptogram does not yield to a multi- 
literal solution. Thus because of its digraphic charac- 
teristics, it most likely is digraphie. 

c. In those cases where the ciphertext under 
study is trigraphic, similar general rules apply. 

(1) Message length, repetitions, and interven- 
ing distance are usually multiples of three. 


CONFIDENTIAL— 10-5 


CONFIDENTIAL 


(2) Repetition usually begins with the first 
letter and ends with the third letter of the trigraphic 
ciphertext. 

(3) If the cryptogram does not yield to solution 
of triliteral ciphers, it can be assumed to be tri- 
graphic because of its characteristics discussed above. 

d. Should the above listed characteristics prove 
inconclusive, initial identification may be made 
through the use of the statistical test and table 
which is covered in the following paragraph. 


10-6. (YZ) The Digraphic Lambda (X) Test 


a. The digraphic blank expectation test, in all 
respects, except the form of the element treated, is 
the same as that for the monographic blank expec- 
tation test. Both rest on the theory that, given a 
certain length of plaintext and a predictable number 
of blanks, the nonusage of a letter will occur. The 
occurrences refer both to that expected for plaintext 
and random text, and in this test are based on di- 
graphic elements rather than individual letters, as 
was the case of the former test. Again 200 elements, 
in this case digraphs, set the limit of messages which 
may be tested. Tests of messages greater than 200 
elements in length are inconclusive. The digraphic 
test is given in chart form below in figure 10-8. 


Figure 10-8 (U). Digraphic Lambda (A) test (U). 


b. Using this chart, identification is based upon 
the number of blanks, where a blank is a nonoccur- 
rence of a digraph, occurring in a cipher message 
not exceeding 200 digraphs in length, in respect to 
the number of blanks, expected in plaintext and 
random messages of the same length. As can be 


seen, the chart contains two curves; curve P refers 
to expected blanks for plaintext and curve R refers 
to expected blanks for random text. In using the 
chart, plot the point of intersection of the vertical 
line (corresponding to the total number of digraphs 
in a given message) with the horizontal line which 
corresponds to the total number of blanks occurring 
in that message. If this point of intersection falls 
closer to curve P than it does to curve R, it indicates 
that the cryptogram is digraphic. If it falls closer 
to curve R than curve P, a nondigraphic substitution 
cipher is indicated. 

c. A cipher which is polyalphabetic and which 
involves only twe cipher components gives essentially 
the same results as a cipher which is truly digraphic. 
For this reason this test should not be used exclusively 
for the identification of a digraphic system, but 
rather to substantiate other evidence. 

d. Where it becomes necessary to distinguish 
between a digraphic cipher and a polyalphabetic 
cipher using two cipher components, a digraphic 
frequency distribution could be made ‘‘off the cut,” 
i.e. made of those ciphertext digraphs which are 
found by omitting the first letter of text, then 
dividing the remaining text into groups of two letters. 
If the system is digraphic, a distribution exhibits 
a poor 2¢0; if, on the other hand, it is polyalphabetic, 
the 2¢0 is as satisfactory as that of a distribution 


made “on Ahe cut.” 
10-7. ve he Digraphic Phi Test (2¢0) 


* 


a. The computation of the value of 240, 2¢p, ana 
2¢r for this test is the same as that given in para- 
graph 9-7 preceding. The difference lies in its use for 
the identification of digraphic systems and the 
interpretation of its resultant values. In digraphic 
systems involving substitution where all the letters 
of the alphabet are used, except the limitation im- 
posed by a 25-cell matrix, the value computed for 
2¢0 approaches that of 2¢p for English plaintext 
which is 4.66. 

b. Note again that the results of digraphic tests 
are subject to much wider variation than similar tests 
for monographic systems. Factors which contribute 
to this are the limited number of digraphs, of a 
possible 625, which may be required to encipher the 
text, and the presence of repeated digraphs in the 
text which further reduce the total number of 
digraphs. The end result is that statistical results 
must be used with caution. 


10-8. Identification of the Specific System 

a. Once the initial recognition of a cipher message 
as a polygraphic cipher has been accomplished, the 
next step preparatory to analysis is the identification 
of the specific system to which it belongs. This 


10-6 GONFIDENTIAL 


identification can frequently be made on the basis of 
certain characteristics of the ciphertext which result 
from the method of encipherment. These individual 
characteristics are listed below. 

(1) Four-square ciphers. The identification of a 
cipher message as the product of this system rests 
generally on a process of eliminating other digraphic 
systems as possibilities. This is not to mean that the 
text itself does not exhibit characteristics of its own. 
It does, but the identification of these characteristics 
are not as readily apparent and involve detailed 
study, while the characteristics of the other systems 
can often be noted by a visual inspection alone. 

(2) Two-square system. Two-square systems are 
identified by the presence of plaintext digraphs in 
the ciphertext. Under normal circumstances approxi- 
mately 20 percent of all digraphs produced by this 
system will be plaintext. In the specific case of a 
horizontal two-square system, the digraphs will be 
reversed. In the case of vertical two-square encipher- 
ment, the plaintext digraphs will occur in their 
original sequence. 


(3) Playfair ciphers. A cipher produced by this 
system is generally identified by the complete absence 
of digraphs containing repeated letters. The reason 
for the absence of repeated letters as digraphs is a 
consequence of the fourth rule of the encipherment 
given in paragraph 10-3d(4). 

(4) Large tables. Because of the systematic 
arrangement of the internal cipher values in tables 
such as that illustrated in figure 10-2 preceding, 
identification is made by a simple uniliteral frequency 
distribution of the letters of the cipher digraphs. For 
example, note that any plaintext digraph ending in A 
contains Ge as the last letter of the cipher digraph; 
thus AAp=WGc, BAp=£Gc, etc. Other arrange- 
ments which are symmetrical would give similar 
results. 


b. The above examples often allow identification 
by visual inspection alone. Where this is not possible, 
the analysi must study a given cipher in detail using 
procedures which are covered in succeeding para- 


graphs. 


CONFIDENTIAL— 10-7 


CONFIDENTIAL— 


CHAPTER 11 
SOLUTION OF POLYGRAPHIC SUBSTITUTION SYSTEMS 


Section I. 


11-1. is Introduction 


a. The fundamental purpose of polygraphic sub- 
stitution is the suppression or total elimination of 
the frequency characteristics of ordinary plaintext, 
for it is these frequency characteristics which lead, 
sooner or later, to the solution of practically all 
substitution ciphers. The’ analysis of cryptograms 
which are the result of polygraphic substitution 
rests upon the basis of the frequency of the units 
concerned. If the substitution is digraphic, the units 
studied are pairs of letters and the normal frequencies 
of plaintext pairs become of primary concern. If 
the system is trigraphic, the units are sets of three 
letters, etc. 

6. Although analysis is chiefly a case of studying 
frequencies, additional aid is provided by certain 
digraphic idiomorphs, which are the result of the 
‘particular method of digraphic encipherment used. 


) ANALYSIS OF DIGRAPHIC CIPHERS 


Additionally, any knowledge available to the analyst 
in respect to the subject, possible contents, and the 
circumstances surrounding a given message are 
always invaluable in reaching a final solution. In 
any case, when a digraph is used regularly, sufficient 
messages soon accumulate to the point of solution 
by principles of frequency. In this respect note that 
the “sufficient quantity’? varies. In some cases, 
where digraphic idiomorphism is pronounced, and 
when a number of repetitions are available, solution 
may be practical with only a few messages. 

c. In digraphic systems in particular, the identifi- 
cation of only a few cipher digraphs is usually 
sufficient to read out longer portions of the messages. 
This is due to the limitation placed on the value 
that can be inserted between those high-frequency 
values normally first recovered. For example. con- — 
sider the following, a portion of digraphie ciphertext 
with its recovered plaintext values. 


XQVOZILK AP OL ZX PV CK [IK OL UK AT 


ND IN NT 


HN LK VL BN OZ BZ DY 
ON TO 


IN SI 


d. With a little imagination, the partially re- 
covered plaintext could be expanded to “SECOND 
INFANTRY REGIMENT.” Moreover, if CAc= 
GIp then possibly Gic=CKp, the last portion of 
the message subject “ATTACK.” On this basis the 
sequence might be: 


“SECOND INFANTRY REGIMENT NOT 
YET IN POSITION TO ATTACK.” 


_ Although these values rest on an assumption only, 
their validity could soon be verified; first, by at- 
tempting additional decipherment, and second, by 
fitting the values into the matrix which originally 
produced them. 

e. In a manner similar to uniliteral systems, the 
placement of repeated digraphs at once aids and 
limits the choice of probable words. For example, 
the following repetition extracted from a message 
appears possible as a whole word. 


RE NT NO 
TY LE GI 


VI FW HM AZ FF FW RO 


In terms of digraphic idiomorphs it would be 
assigned the pattern 


AB — - — AB 


This pattern compared to those listed in appendix 
D (table D—4) reveals several possible words which 
could be used to form a base for further development 
of the text, by trying the set of values derived from 
each, in turn, 


11-2. g Identification of Four-Square Ciphers 


a. Te general steps and techniques involved in 
the analysis and solution of a four-square cipher 
system are demonstrated below. Admittedly, the 
situation given represents a special case in that the 
solution is based on one message. However, the 
methodology remains the same for most cases, 


-CONFIDENTIAL — 11-1 


468-095 O-~ 72-10 


CONFIDENTIAL- 


only slight variation being required to fit it to any 
given set of circumstances. The first step in any 
analytic attack is system identification. The follow- 


ing messages illustrate identification techniques 
employed in the case of four-square ciphers and 
subsequent analysis. 


UNONY TPKKM JKZDK 
RCIJCP YDEBC DFHMR 
YTUFE. UUFUE FAYVD 
YPRCJ CPYDE BCDFP 
HMUNE MRUAS SAPSK 
JNNSA RKDEM REFGP 
PTUDB BDG@GLM FAPSF 
KMTGJ GTJUN BFNJO 


JISGR TGLWR AEMYP 
MKGZA PKPSK MUNON 
AMTDM UDPEY PPYEM 
SYKNE TJIJSZO UDRJIG 
MRLHS BROUN EETUO 
EHMDE AMKAJ GEMQJ 
JPTFF BMDCG TSGPS 
NUNNT 


b. As a preliminary step, the cipher is tested for 
monoalphabetic qualities by using standard alpha- 
bets and by completing the plain component as 
shown in paragraph 7-12. As negative results are 


=2_#_=+= =.= 
sz 22222 # = 
ARG 8 aoe BPs - KE 
1077 14 16 


obtained, a uniliteral frequency distribution is 
made as shown in figure 11-1 to determine if a 
mixed alphabet is involved. 


o THETA 
© || 


12 12 14014 12 3181461929 121214110 10 3 


Figure 11-1 (U). Uniliteral frequency distribution, four-square cipher (U). 


Although the uniliteral frequency distribution ap- 
pears rough enough to warrant an initial mono- 
alphabetic assumption, closer inspection reveals that 
except for three letters there is really little frequency 
variation, less than might be expected for a message 
of this length. A ¢ test could be made if further 
identification is required, but considering’ the size 
of the sample and its apparent flatness, it is hardly 


ne Se oe ae 


UN_ON YT 
RC_JC PY 
YT UF EU 
YP RC JC 
HM UN EM 
JN NS AR XD EM 
PY UD BB DG Lif 


KM TG JG TJ UW 


PK KM 
DE BC 
UF UE 
PY DE 
RU AS 


JK 
DE 
FA 
BC 
SA 
RE 
FA 
BF 


Bawa vaAw Pe 


ZD 
Ati 
YV 
CF 
PS 
FG PE 
PS Fd 
NJ ON 


warranted. 

c. Having rejected monoalphabetic substitution, 
there is no need to consider transposition, as the 
message is not rearranged plaintext. Digraphic sub- 
stitution is the next logical consideration. For this, 
the ciphertext is divided into digraphic units. Re- 
peats are underlined and inspected for idiomorphic 
characteristics as shown in figure 11-2@). 


HO: 23) Te 5 
Kd 
fu 
DA 
PS 
KM 


JS 
KG 
“lT 
YK 
RL 
AM 
PT 
UN 


GR TG 
ZA PK 


LW RA EM YP 
PS Kit UN ON 
Dif UD PE YP PY Eli 
NE Te SZ OU DR IG 
HS BR OU WE ET UO 
DE AM KA JG EM QJ 
FF BM DC GI SG PS 
NT Fic 


Figure 11-2@ fh Cipher text prepared for analysis (U). 


d. On the strength of the digraphic patterns 
exhibited by the text, divisible by two, and repeti- 
tions consisting of digraphs, it can be assumed to 


11-2 


be a digraphic cipher. Confirmation of this assump- 
tion can be obtained by constructing a digraphic 
frequency distribution as shown in figure 11-2@). 


| _ta facto te les fati fs fete nto ie tatnls frjoly x et 
REC EC Tere 


FF-1 a tg ale dala sleek todasla feo) loth se 


eee — ie ee 
ac PEt TT to 
zi eee 


Figure 11-2@ fp. Digraphic frequency distribution (U). 


e. The appearance of this distribution shows some 
characteristics of digraphic substitution. Given an 
alphabet of 26 letters, there are 676 possible di- 
graphic combinations. For an alphabet of 25 letters, 
there are 625 possible combinations. Of these, only 
about 300 are used in normal plaintext. In the 
message above, only 74 different digraphs are used, 
602 total blanks assumed. For a message of 74 
digraphs, the normally expected number of blanks 
given by the digraphic Lambda table falls within 


the range 617 for plaintext and 606 for random text. 
With such a small sample as this, the expected 
pattern is liable to be distorted. However, consider- 
ing the number of repeated sequences in such a 
short message and the obvious absence of several 
letters, the nearness of observed blanks to expected 
blanks for random text may be explained in part. 
Furthermore, a digraphic ¢ test reflects the same 
condition with the observed digraphic Phi value 
(2¢0) of 136 surpassing that expected for plain 


CONFIDENTIAL — 11-3 


(2p) 106.95, the expected random value (2¢) 
being 23.25. Note that when a digraph frequency 
table is used, as in figure 11-2@ the value of F is 
found in each cell. For example, in the first column 
2 is found for the digraph FA, thus F(C—1) =2x1=2 
for this column. To find the total, the total values 
of each column are then added. 


11-3. (2 Analysis of Four-Square Ciphers 

a. Accepting the system as digraphic, reexamina- 
tion of the text reveals a doublet, the digraph FF; 
therefore, a Playfair cipher can be discounted. In 
two-square ciphers 20 percent of the total text 
would be plaintext, normal in the case of a vertical 
arrangement and reversed if the arrangement of 
the matrices were horizontal. Failing to note any 
great number of obvious plaintext digraphs, normal 
or reversed, the analyst can assume that a four- 
square system is represented. Accordingly, a matrix 
can be constructed as shown in figure 11-3. Direct 
standard alphabets are used for 12p, as this is the 
normal arrangement, the I and J are combined 
because of the absence of the former in the di- 
graphic frequency distribution. 


lalBi{ci{pieit | | | | 
FictHp{stkiit | ft 
EAE Te 
fataistt fui 

teeter 
= eee 


Pl Cl 


Ce 


ot tt ig tea ist ti yl 
ea 


Figure 11-3 Jp. Assumed plain component, four-square 
matriz (U). 


GG) aoe back to the ciphertext, the repeat 
PS KM appears three times at rather regular inter- 
‘vals in the text. By position it seems to be a sentence 
separator and being of four letters the word STOP 
is immediately assumed. Thus PSc is assumed to be 
STp and KMc is OPp. These values are accordingly 
inserted in the matrix, figure 11-4. 


LM TN | 
Ca tet tate 
PT x Ty 


Figure 11-4 (C). Insertion of cipher values (U). 


(2) The placement of these cipher equivalents 
allows the assumption of fourth placement by 
position alone. Generally the cipher component can 
be a standard sequence, a mixed sequence, or a 
random sequence. Further it may be inscribed into 
the matrix by a number of different routes. If the 
alphabet is standard, or keyword mixed, it is very 
likely that the last letters, the V-W-X-Y-Z cluster 
is undisturbed in respect to sequence, and if so will 
fall at the end of the inscription route. If the route of 
inscription can be determined, these letters can be 
placed with a certain degree of certainty. The direc- 
tion of a route may sometimes be determined by the 
placement of the cluster letters. For example, the 
relative position of Ke and Pe in sequence C1 can 
be considered in a former light. Normally, four 
letters separate K and P (K L MN O P):; if normal 
horizontal inscription is assumed for this square, 
three blank cells are found where four are required. 
Therefore it can be one of the following conditions. 

(a) The route of inscription is something 
other than normal horizontal. 

(6) That portion of the cipher component 
containing K and P is either mixed or has a letter 
missing, the letter being used in the keyword. 

(c) Both (1) and (2) are in effect. 

The first option is disproved by a simple count. The 
third cannot yet be disproved. In counting. however, 
it is observed that A appears in the 15th position 
when normally it occurs at the 11th. This means 
that four letters normally following it must now 
precede it. If this is so, a missing letter between K 
and P would account for only the three cells present. 
Furthermore, P which normally occurs at the 16th 


11-4 CONFIDENTIAL— 


~CONFIDENTFIAL— 


position is so located to provide space for only six 
following letters, indicating that four letters nor- 
mally following it now come before. Thus, four of the 
letters shown below must precede the K: 


KLMNOPQRSTUVWRYZ 


1 missing 4 missing 


(3) Considering which letters can be missing in 
the light of their normal frequency of use may prove 
useful. Between K and P, 0 is probably that missing 
letter since it may be part of a keyword. From P to 
Z: RSTU or perhaps, QU and two of the cluster 
RST may be missing. The choice here with more 
letters, is more difficult. One aspect, however, is that 
the missing letters are probably not VWXYZ. On 
this basis, placements may be assumed as follows: 


Cl 
K 
L MNP 
VWXYZ 


(4) By applying the same line of reasoning to 
the placement of cipher elements in the C2 square, 
the additional placements may also be assumed, 


123 45 6 7 


A -Uil_ OW _YT PK KM JK ZD 
YT OP 
B RC JC PY LE BC _DF HM 
TY 
C YY UF EU UF VE FA YV 
YT VY 
D YP RC JC PY DE BC DF 
TY 
E HM UN EM RU AS SA PS 
ST 
F JN NS AR KD EM RE FG 
SS 
G PY UD BB DG LM FA PS 
TT ST 
H KM TG JG TJ UN BF NJ 
OP 


giving a partially completed matrix as seen in figure 
11-5. 


ABICIDIET TT tt | 
ptt tT 
BRD BRR 
QIRISITIUE LIM apy | 


PTT palelclple 
PCr 
I ATC 
S500 Besar 
riba vbw bete i 


Pl 


Pe 


Figure 11-6 vA Placement of cipher values by assumption of 
‘ sequence (U). 


(5) To this point, assumption hus been added 
to assumption, a sometimes dangerous practice but 
one which can be rectified quickly by checking the 
assumptions against the ciphertext, figure 11-6. 


8 9 10 11 12 13 14 15 


KJ JS GR TG LW RA 
RV 

PS KM 
5ST OP 


PE YP 


EM YP 


RU KG ZA UN ON 


MP PY EM 


SZ OU DR JG 
OU WE 
KA JG 
DC GT 


NT 
TS 


Figure 11-6 (C). First partial reconstruction of plaintext (U). 


6. No impossible combinations have occurred to 
disprove the assumptions relative to the placement 
of letters in the matrix. However, little insight has 
been gained into the message text. The next step 
then is to build on the digraphs recovered, attempting 
to assume additional values. This can be done easily 
if the positional limitation placed on one member of 
a cipher pair by the other member is considered. For 
example, consider the cipher digraphs PK KM 
located at positions A4 and 5. The positional limi- 


CONFIDENTIAL — 


tations in this case are such that PKe must equal 
some combination of the row QRSTU of the Pl 
matrix and columns D J O T Y of the P2 matrix. 
The location of PKe in the_ciphertext and the re- 
covered values for YTe and AMe which flank it, plus 
self-limitation imposed by impressible combinations, 
QD, QT, ete., limits the choice. If a plain value of 
ROp was accepted for PKce, the word TROOP would 
be completed as a possibility. Thus A can be placed 
in matrix C2. 


11-5 


GONFIDENTIAL 


c. Another method of determining values is 
possible, through a study of absolute frequencies 
considered in the light of possible limitations of 
location. For example, the ten most frequently used 
English plaintext digraphs are: EN, RE, ER, NT, 
TH, ON, IN, TE, AN, and OR. Referring back to 
the digraphic frequency distribution, the digraphs 
EMce, PSc, UNe, and KMc are the most frequently 
observed. Again considering the limitation imposed 
by the location_of Me in matrix C2, note that EMe 
can only equal INp or ONp. IMp and OMp are also 
possibilities but are discounted by frequency. This 
limitation can be seen clearly in the partially recon- 
structed matrix shown to the right. 


ABCDE 
Pi J (E) 
O (E) Cl 
T 
Y 
C2 M LMNOP P2 


(1) For the moment, that digraph with the 
highest frequency can be accepted, EMe=INp. 
Another method of determining values is through 
the arbitrary assumption of words conditioned by 
logic, and then testing the values so determined. 
For example, consider the opening line of the 
message with plaintext values previously assumed. 


10 : 15 


A UN ON YT PK KM JK ZD KJ JS CR TG LW RA EM UP 


YT RO OP 


(2) Four elements are present in the plaintext 
sequence above which muy lead to the further 
recovery of values. YT is obviously a word bridge; 
therefore, the digraphs UNe and ONe must repre- 
sent the rest of the word which refers to TROOP. 
A possible word is ENEMY, and if this is valid 
there, TROOP probably ends in S. If ENEMY 
is correct, then UNe=ENp, and ONc=EMp. 
This can be tested against the matrix as shown in 
figure 11-7. 


ape [OE OTT 

Fictalsie [| (ey I | 
iiMpxor ft [| [ig 
aia Watt 


PEA 
a i ea Cea aS 
Sietehet pont fore 
Cy sire aleis trig 


Pl Cl 


C2 Pe 


Figure 11-7 f Test of cipher value placement (U). 


(3) Note that again the positional limitations 
of the matrix are such that the assumed values 
can easily be placed. Further, the one empty space 
between the K and M of the C2 square allows the 
placement of the L. With the additional values, 


RV IN 


more ciphertext can now be deciphered, 
11-8. 


Bvt. Be SU OOo IR. son “OSG ae GAT tee as 


A Vil ON YP PK hii dK cl wd JS GR YG LW ka EM Wr 
LN IM YT RO OP RV Ti 
B RC JC PY CE BC UF di. Ei KG ZA PE PS Ki UN O04 
TY En EN 
C YT UF EU UF UE FA YV UA iT Dt! UD PE YP PY &t 
YT KS Wy T I 
D YP RC JC PY DE BC OF PS YK NE TJ SE OV ER J 


Qri mes 


[ Hid UN EM RU AS SA PS Ki RL HS BR Oo NE ED UC 


ER Ts 
F Jiu WS AR KD EM RE FG PE Hi DE Atl HA IG EY! Qe? 
SS In aie 
G PT UD BB OG Lif FA PS FI PT FP Bl LC GT SG PS 
TT TL st a2 st 
H MTG JG TI UN BF id ON UN IT 
OP ET oh, Eu TS 


Figure 11-8 (C). Second partial reconstruction of platn- 
text (U). 


d. Again, little is revealed by the recovery of the 
additional value. However, note the idiomorphic 
pattern of the last seven digraphs. 


AB - = - AB 
TJ UN BF NG ON UN NT 
EN EM EN TS 


(1) By checking this pattern against those 
listed in appendix D (table D-4) digraphic idio- 
morphs, it is found that the pattern can represent 
the word REENFORCEMENTS. Note also the 
pattern 


FJ, PT, FF, Row G Column 8, 9, 10 and QJ, PT, UD on Row F-15, G1 and 2. 
TT 


TT 


1-6 CONFIDENTIAL— 


CONFIDENTIAL — 


- Assuming the placement of the “Je to be 2 correct as 
shown below, on the basis of the word TJce=REp 
above, and assuming that TT in each case represents 

_& doublet rather than a word bridge, additional 
values can be derived. For example, inspection of 
the matrix with the J inscribed in its assumed 
position of the C2 square reveals that QJc and Fc 
must equal plaintext digraphs that contain, A, B, 
C, D, or E in the second positions. If Fe is placed in 
the first cell of square C1 FJc would equal BAp. 
This in combination with TT, (BATT) would in 
turn suggest a possible word, BATTALION. 

(2) To complete the word, the plaintext di- 
graphs of AL and IO and N— must_be supplied. 
Note that the prior placement of FFc=Alp, and 
BMc=IlO0p which tend to confirm the former assump- 
tion, leaving DCe to equal N=p. By placing the 
D-e on line three of square C1, it is alined properly 
for the N=p value. However, as there are four pos- 
sible cells in which it may fit, it cannot be exactly 
placed. But since it falls on that line, the last cell of 
the second line must contain a C, the letter imme- 
diately preceding the D alphabetically, figure 11-9. 


Pl rehech ope ty Cl 


[Sn aes ce a 2 con! en Se 
7s 
OE 
Ce 
SUT ioe yes | Tle 
pebebetetet pe trbet ety 


Pe 
C2 


Figure 11-9 ip. Insertion of cipher values through 
analysis (U). 


(3) Referring back to the partial sequence 
shown below and comparing the plaintext values 
shown with the partially recovered matrix, another 
possibility is apparent, the word ATTACK. Note 
the plain equivalent for QJe must. end with A, B, 
C, D, or E plain, and that the plain equivalent for 
UDe must begin with A, B, C, D, or E plain, thus 
placing an A on either side of the double T. 


EM QJ PT UD BB 
IN TT 
(4) Referring back to the sequence EM QJ 


IN 
PT UD and considering possible equivalent v alues, 


eT 

another word is suggested. Note that the plain 
equivalent for QJe must end with A, B, C, D, or 
E. Similarly, the equivalent for UDe must begin 
with the same letter. Thus an A may be placed to 
either side of the doublet (ATTA) suggesting 

ATTACK. Inspection o| of the matrix shows that the 
required values of ACp for UDe can be made by 
placing D in cell one, row one of square C2. The 
Qe can then be placed in cell one of either the second 
or third row, square Cl. In order to derive a K 
plain, the cipher digraph BBe must equal K-p. 
Note that the positions of the B=c and K=p are such 
that Be must appear in the last cell of rows one an 
two of square C2. 

e. At this point the analysis can take one or a 
combination of three courses, all involving tech- 
niques previously discussed. The analyst can at- 
tempt a recovery of the keyword alphabet used in 
the C1 and C2 squares. He may continue the process 
above, patiently reconstructing plaintext by exam- 
ining patterns, assuming possible words, then check- 
ing their possibility against the matrix. The last 
method is simply one of attempting to decipher 
additional bits of the message as recovery of the 
matrix progresses. For example, using the matrix 
shown in figure 11-10@ which incorporates values 
previously found, the message can now be deciph- 
ered in part, figure 11-10@, to read as shown. 


PL C7) 


Ce 


FEV al Hf ei OTe P2 
Ct sir ares trial 


Figure 11-10@ (@). Partially recovered four-square 
matriz (U). 


CONFIDENTIAL—__ 11-7 


CONFIDENTIAL— 


123 4 5 6 7 8 910 11 12-73 14 15 


A Uil ON ¥T PK KM JK aD KJ JS GR TG ZW RA Eli YP 


EN EM YT RO OP(MO)VE ME(NT) RV Ili 
B RC JC PY DE BC DF Hi RM KG 24 PK PS kti UN Oil 
TY (ZE)RO ST OP EN EM 
C T UP EU UF UE FA YV DA MT DM UD PE YP PY EM 
YT AN KS AN vy TR AC TY I 
D YP RC JC PY DE BC DF PS YK NE Td SZ OV UR dG 
TY ST WO(TE)RE(IZ)ER(O) 
E Hil Ui EM RU AS SA PS Ki! RL HS BR OU NE ET UO 
EN In ST OP ER IS 
F J NS AR KD El! RE FG PE Hl DE AM KA JG EM Qi 
G 
SS LE IN IN MA 
G PT UD BB DG LM OFA PS FJ PT FF Bit DC GT SG PS 
TT AC KI(WA)TL(EA)ST BA TT AL IO ST 


H Ki TG JG Td UN) BF lJ ON UN UT 
OP(SE ND)RE EN FO RC EM EN TS 


Figure 11-10@ (C). Partially recovered plaintext (U). 


Section Il. (Z) ANALYSIS 


11-4. (Z) General 


a, The initial identification and subsequent analy- 
sis of two-square systems is contingent upon the 
recognition of their one primary characteristic, that 
20 percent of all cipher digraphs are in fact trans- 
parencies, i.e. the same as the underlying plaintext. 
In the case of vertical two-square systems, these 
transparencies will be identical with the plaintext 
they represent; while in the case of a horizontal two- 
’ square, the transparencies will be reversed. Thus, if 
the examination of one or more cryptograms results 
in the consistent observation of digraphs which form 
good plaintext digraphs they may be assumed to be 
the result of encipherment by a two-square cipher 
system. 

5. The preliminary steps covered in the preceding 
section, that is, the assumption and rejection of the 
system being monographic and uniliteral encipher- 
ment, are followed as a matter of course. After these 
rejections, the ciphertext is examined closely for 
those characteristics given for digraphic cipher 
systems. The normal digraphic tests are conducted 
as required in order to aid in ascertaining whether 
the system is digraphic. Once this has been accom- 
plished, the analyst is again faced with determining 
which specific system was used. 

ce. It is usually possible to make a final determina- 
tion as to whether a cipher represents a two-square 
horizontal, or a two-square vertical, by a visual 
examination of the text. Sometimes the structure 
of the system is such that skeletons of words or 
whole phrases are readily apparent. However, this 
is the exception to the rule. Without some kind of a 
formal test, it is difficult to specify what constitutes 
a “good. amount” of plaintext digraphs for identifi- 
cation. Such a test is illustrated in the succeeding 
paragraph. 


As several more words are now obvious (shown in 
parentheses) additional values could be recovered 
quickly using the techniques previously shown, the 
solution becoming a mechanical process. 


OF TWO-SQUARE CIPHERS 


11-5. (Y Two-Square Test 


a. The test to be described is based upon an 
evaluation of the observed frequency of a given 
ciphertext digraph in terms of its expected frequency 
as a plaintext digraph. Any such correlation as 
might exist between a given plaintext digraph and 
its occurrence as a cipher digraph produced by a 
four-square, a Playfair, or a large-table system, is 
acciderital. But in the case of a two-square system, 
the correlation is the result of the mechanics of the 
enciphering system. Thus, if a ciphertext digraph 
exhibits only the random expected occurrence, 
considered as direct and reversed transparencies, 
then that ciphertext may be assumed to be the prod- 
uct of a digraphic system other than a two-square. 
If however, the number of occurrences exceeds that 
random expected value, the ciphertext may be the 
product of a two-square system. Of course the mode, 
as direct or reversed transparencies, in which this 
greater value occurs, indicates the particular system 
used. 

b. To illustrate the procedures involved in this 
text, and the techniques of subsequent analysis, 
the following ciphertext, figure 11-11, prepared 
for study, will be used. 


123 46 5 6 7 8 9 10611 1223 14 45 


WO HL OR AH OP Ali QN AM IP EV FA Hi QC 
St HE PO QB LH RI tlE SY EB SS HC DF OZ 
BP Al KQ SH QN WO ER UQ OI UT 


w 
*. 
s 
= 


afh3 
S]H 
| Uy 
ty 


| 
ISK 


A BO DL EM QB EP EL QH HO PE LO AQ CL IL NU OT 
5 PH TA GB OTB AM WA OL UC SEOUL PC SE NT Ab TA 
C WY BE GE HL CK TC Si PH RI OD HE UC OL TH i 

D DE FC PP Eid NE YA IP EV PA ate QC TI SE S2i Gi 
rs GR SP PB SS AB LF HL OR Ai’ OP A?’ ON HL EC RN 
F OS AH PH SI NB TB AN MA OT QH GE NO RN ES cl 
G SP BB EM IN TA SE Si YD RK EB NG At! WN Ai: DE 
h 

ZL: 

J 


Figure 11-11 (C). Ciphertezt for analysis (U). 


11-8 CONFIDENTIAL 


CONFIDENTIAL 


(1) Preliminary to a study of the digraphs as of the digraphs is tabulated using the normal 
“direct”? or reversed transparencies, the frequency digraphic frequency matrix shown in figure 11-12. 


P Taye {c qo fe fF [c Tayi fs [k [te [M [Nn To Tp [a [Rr Js Tr Juv [wxty[zq 
eho et 


me ms = 
Hiab hsb hbiiabets ete bteehht— 


Figure 11-12 (U). Digraphic frequency matriz (U). 


(2) Once the digraphs have been tabulated, the Column 3 Logarithm of expected  fre- 
individual digraphs may be listed in alphabetic order quency of digraph as direct 
and tested for their probability as direct or reversed plaintext 
transparencies. The format of the test is shown in Calms Producvat Coan <3 


figure 11~13. Column identity is: 
Column 1 Ciphertext digraph 
Column 2 Frequency of digraph in text 
from digraphic frequency dis- 
tribution Column 6 Product of Column 2 x 5 


CONFIDENTIAL — 11-9 


Column 5 Logarithm of expected frequen- 
cy of digraph as reversed 
plaintext 


(ay: CB) 43). oC: <0) 06) 


1.45 45 (£38 38 
An ~ 3: 425 iTS... wot 2s01 
OM 3 46. | 66 S78 COSTE 
AQ 1 0 @) ) 0 
BB 1 ) 0 . 0 9) 
BE 1 66 .66 .38 38 
BF 1 Ci. lO @) 6) 
BO 1 38 736. 438 38 
CK 1 38. «38 <13 13 
pO 2% 38 38 = .13 13 
DE 3 77 2.31 .88 2.64 
DL 1 33% 433) «23 <3 
po ol 63 63 .58 58 
EB 2 38 .76 .66 1.32 
EL 1 7 .74 = .79~=~.79 
EM 3 61 1.83 .72 2.16 
EP 1 67 67 <TOc «0 
ER 1 94 8.94 96 96 
ES 1 86 .86 84 84 
EV 2 67 1.34 .87 1.74 
FCO 1 25 $25: add: «23 
GB ol Or yi. “ge GE ae 
GE 1 61 61 .38 38.38 
GL 1 25 25 .13 .13 
GR 21 ho Kaw UBCWC 
HC 2 33 .66 .61 1.22 
HL 6 13 78 .13~=~.78 
HM 2 25 50 .13 .26 
TH 1 9) ony S ies Ae 
IL 2 70 -70. .67 .67 
IP 2 48.96 US .90 
KM 1 0) Oo . 0 
KQ 1 fe) OF oO! «48 
LF 1 33 6330 5525 £25 
LH ol 13 Pia hc Sam CS es 
LN ay 13 13. 42 42 
MA 2 78 1.56 .61 1.22 
ME 2 72 1.44 .61 1.22 
MI ol Ge. is? . 6 -Gi- a0 
ML ol 9) QO .25 25 
MU oo 25 .25 =~.42 he 
NB 2 25 250 .0 ?) 


WE Ol 87 87 .99 99 
NJ 2 13 .26 ) 0 
wn 4 5.1 2.04 .51 2.04 
no 64 66 2.64 .92 3.68 
OE itl 33 533° 256 58 
Ol 5 13 65 .25 1.25 
OP 2 72. 2.44 .64- 1,28 
OR 2 89 1.78 .74 1.48 
os ol 61 61 .62 62 
OZ. 4 0 ead) ©) ) 
Pe 1 13 .13 @) fe) 
PH 2 33 66 .13 26 
PO 2 64 1.28 .72 1.44 
PP ul 56 56 .56 56 
QB 3 @) 0 6) 9) 
ac 8 @) Pay 0 0 
QE 2 fe) SO (433 26 
QM 3 13 239 ) 0 
RA ol 80 80 .82 82 
RB 1 25 25 «625 25 
RE 1 33 33 64 64 
RI 2 15 - 2s50- “TS 2eh6 
RK ol 13 pbo . a 9) 
RQ 1 @) oO 453 13 
SE 5 84 4.20 .86 4.30 
SH. 2 «wre 72 =.38 38 
SI 1 TT -1T 78 78 
sn 3 .38 $1.14 .71 2.13 
SP 2 .55 1.10 .45 90 
ss 2 67 1.34 .67 £21.34 
sx. 2 0 . QO .13 13 
TA 4 7h 2.96 .83 3.32 
T 2 33 .66 .13 26 
ro. <2 k5 450.61 61 
TI 2 82 1.64 .73 1.46 
uc. 2 33 yoo RSS 38 
YA. 2 4s 45 158 58 
YD 1 53 53° ads 13 


Figure 11-13 (U). Test for probability of transparencies (U). 


(3) As the total value of all digraphs as reversed 
transparencies (the sum of column six) is greater 
than that for the digraphs as direct transparencies 
(column five) it can be assumed then that the system 
involved is a horizontal two-square. If the value of 
direct transparencies had been greater, the assump- 
tion would be for a vertical two-square system. 
Under normal circumstances, a horizontal two-square 


11-10 


produces N x 0.3388 reversed transparencies, while a 
vertical two-square produces N x .3610 direct trans- 
parencies. (N in both cases refers to the number of 
digraphs.) In this case, the theoretical value of 
expected reversed transparencies is 4.9126 (145 x 
.3388) which compares favorably with 4.15, the value 
observed as difference between columns five and six. 


-GONFIDENTIAL— 


GONFIDENTIAE 


11-6. Analysis of Two-Square Systems 

a. The solution of both the vertical and horizontal] 
two-square systems involves the same general 
principles and techniques. Only a slight modification 
in the reconstruction matrix is required to orient it 
vertically or horizontally as the case may require. 
The first step in either case, is to set up the recon- 
struction matrix, and to examine the text closely for 
significant characteristics. Where two-square systems 
are dealt with, an obvious quick entry into the cipher 
is by way of the transparencies. If entry can be made 
by this route, other more laborious and time- 
consuming methods, similar to those illustrated in 
the case of a four-square system, may be avoided. 
With this in mind, the text is inspected for possible 
transparencies. 

(1) The following possible transparencies (fig. 
11-14@) are noted. Although at first glance they 
appear unlikely, consider what occurs when one or 
more digraphs of each are reversed, as in figure 
11-14. 


PH TA 
PH SI 
HL PO 


EM ME YA 


NO ER UQ OI UT 


Figure 11-14@ (C). Possible transparencies from cipher- 


text (U). 
PH AT THAT 
PH IS THIS 
HL OP STOP 
EM EM YA ENEMY 
ON REQU OI UT ON REQUEST 


Figure 11-14@ . Possible transparencies reversed (U’). 


The rearrangement of each digraph makes obvious 
a possible word, shown to the right above. Using 
these assumed values, a reconstruction matrix can 
be set up. 

(2) The matrix used should be of sufficient 
size in height and width to allow the free movement 


CONFIDENTIAL 


Pl C2 


of the letters and to avoid the establishment of 
false relationships. A dividing line, horizontal or 
vertical as required, will provide for the separation 
of the letters. The placement of the letters within 
the matrix can be determined by their use, i.e. in 
a horizontal two-square transparency they will lie 
on the same row; in a vertical two-square trans- 
parency they will lie in the same column. Thus the 
letters T and A must lie in one row, and J and S 
must lie in another row; and as they appear as 
reversed transparencies, A and J would appear in 
square P1 C2, and T and S in P2 C1. All values are 
checked and inscribed in a working matrix and 
appear as shown in figure 11-15. 


Figure 11-16 VA . Preliminary reconstruction matriz (U). 


(3) With some values assumed in the rows 
of the matrix, the next step is to attempt rearrange- 
ment _to obtain columnar order. To illustrate, 
HL PO is assumed to be the cipher value of ST OP; 
thus, encipherment of the first plaintext digraph 
must have occurred in one of the following positions; 
figure 11-16. 


or Cea Pe 


Figure 11-16 of Analysis of cipher-plain value location (U). 


Either method of encipherment demonstrates that 
T and H lie in the same column of square P2 Cl, and 
Sand Lin P1 C2. As both T and S have been placed, 
H and L can be placed in their respective rows, 
figure 11-17. Note that care must be exercised not to 
place a letter in the same row or column with another 
unless some evidence exists to support this placement. 


11-11 


CONFIDENTIAL — 


P1-C2 P2-C1 


Figure 11-17 (%). First expansion of reconstruction 
matriz (U). 


(4) With T and Hin the same row, the digraph 
pairs PHc, TAc, and PHe SIc can be checked. As- 
suming PHe to be THp, encipherment is possible by: 


Pi-C2 P2-C1 Pi1-C2 P2-Cl 
T |P HH: dQ 
ear seers ole 


H\# T P 


In either case it is found that T and P and H and H 
appear in the same rows; that T and HW and A and P 
lie in the same column. By incorporating this rela- 
tionship with that previously established, the matrix 


will now appear as shown in figure 11-18. 
P1-C2 P2-C1 


Figure 11-18 b. Second exnransion of reconstruction 
matriz (UV). 
Position E7-13 HL OR AH 
ST RO (NG) 
D7-13 IP EV RA 


G1-7 SP Bs 


(1) In the first sequence above, a possible word 
in STRONG POINT is easily visible. In the second 
and third cases, no word is apparent, except pos- 
sibly POSITION in the second. However, note the 


(5) The assumed ENEMY for the cipher di- 
graphs HM ME YA provides a further clue. Note that 
EMc, Ec, and Me lie at opposite corners of a rectangle. 
Thus Ep and Mp must lie at the diagonally opposite 
corners. Mp in P1-C2 represents a new placement 
falling below E. Ee of P2-C1, however, has been 
previously placed, thus when it is moved up to its 
proper position to the opposite diagonal corner, R or 
P1-C2 of the same row must also be brought up. 
The matrix, 1earranged to show this relationship is 
shown in figure 11-19 


Plo A | ve 
E : : 
C2 R E OME Pe 
tT OM P a 
Q U 
H 
SH ; : 


Figure 11-19 m4 Rearrangement and expansion of reconstruc- 
tion matriz (U). 


6. Further analysis of the ciphertext follows essen- 
tially the same route, with additional values being 
provided by the letters already inscribed in the 
matrix. For example, using the matrix above it is 
possible to find the following sequence of partial 
plaintext in the message: 


OP AM QN HL PO 
PO (IN)(TS) ST OP 
HM QC TI SE SN 
-P (OS)(IT) IO (NS) 
EM LN TA SE SN 
EN AT 10 (NS) 


similarity in the endings. If T7c and SNe are re- 
versed transparencies, the endings produced will be 
similar “TIONS.” The possibility of this being 
correct can be checked by referring to the preceding 


1-12 GONFIDENTIAL 


-GONFIDENTIAL — 


tabulation of expected occurrences of the cipher 
digraph and appendix D (table D-4). Here we find 
the expected occurrences to be: 


Tic 82 SNe 38 
TTce 73  NSe 71 


(2) Obviously the results are inconclusive in 
the case of the reversal of 7Jc; however, when con- 
sidered with IOp and NSp, the 7Tc¢ combination 
seems to outweigh its negative value. Moreover, 
an. additional test, which is always to be preferred, 
is to try it in the system. Using all values assumed 
in the first case and those above, the matrix now 
can be expanded as illustrated in figure 11-20. 


Pl liu IA T A Pe 
2 N S 

C2 3 R —E OME C1 
4 T OM Q P WU 
5 SHE G 
6 Y YX 


Figure 11-20 (Q). Third expansion of reconstruction 
matriz (U). 


c. As analysis continues, the process becomes more 
and more mechanical. The only problem likely to be 
encountered is in reducing the matrix to its original 
dimensions, the danger being that false relationships 
may be established by an arbitrary telescoping. In 
respect to reducing the size of the matrix, it is 
possible to shift rows and columns to put the matrix 
in its correct order, but in so doing the individual 
letters must not be disturbed. For this purpose a 
partially recovered matrix as above usually exhibits 
sufficient characteristics to permit this. For example, 
assuming that a mixed alphabet of some type is used 
in each square, an inspection of the letters of the 
matrix allows the following observation. 

(1) Row three R-E-/-OME contains letters 
so far out of sequence as to suggest a keyword, these 
letters possibly being part of the keyword. Thus it 
may be the first row. 

(2) Row one L---IA/T----- A exhibits 
some alphabeticity if the P1—C2 values are A I L. 
Further, since the A appears in this row, as well as 
I and L, it may be possible to represent that part of 
the alphabet immediately following the keyword, or 
perhaps part of the keyword. In either case it may 
be the second row. 

(3) Row six, containing the Y in both squares, 
can be ‘the last row. Row four, if the T and U are 


_CONFIDENTIAL— 


P1-C2 


not part of the keyword, must precede row six to 
maintain alphabeticity. Row 5, since it contains S 
and H in the first square, must represent a portion of 
the keyword. On the basis of the foregoing assump- 
tions the matrix can now be drawn up as in figure 
11-21. 


Pl RoE OME C1 
: IA | T A 
c2 Sk is G. ~ipe 
TO Mg. ||P Nou 
N S 
Y Y 


Figure 11-21 (f). Initial construction of two-square 
matriz (U). 


d. The same shifting in respect to columns is 
possible. Again, however, individual letters cannot 
be disturbed. In rows three and four of square P2-Cl 
the letters H - - ~ - - G and P - — N seem to be 
reversed in respect to their normal alphabetic order. 
If these letters are juxtaposed according to their 
normal sequence (considering the O to be used in 
the keyword, and maintaining columnar order), this 
square would appear as in figure 11-22. 


Pp2-Cl 


Figure 11-22 (@'). Rearrangement of square P2-CI (Ul). 


(1) A similar inspection of the square Pi-C2 
shows less in the way of alphabetic patterns that 
can be directly interpreted. However, consideration 
of other factors can provide assistance. Having 
assumed a keyword is being used, it can further be 
assumed that the letters VWXYZ probably are not 
used; thus they are the last line. Y then would 
appear in the second column and consequently so 
would A and Q. They begin the same column. Note 
that in row three, O and M are reversed. Thus the 
square can be put in the order shown in figure 11-23. 


11-13 


P2-Cl 


Figure 11-23 Co) . Rearrangement of square P1-C2 (U). 


(2) The two squares in matrix form appear in figure 11-24. 


Pl 
R E 
C2 L I A 
S H 
T MO @Q 
N 
Y (2) 


Pe 


C1 


Figure 11-24 g . Partially recovered horizontal two-square matriz (U). 


e. Matrix reorganization and recovery can be 
continued or the analysis of the ciphertext can be 
resumed. Sometimes recovery aids in the final 
solution as it provides a true framework for the 
insertion of additional values as they are found, 
thus avoiding the possibility of establishing false 


relationship. On the other hand, the paucity of values 
recovered in an intitial entry and the use of a random 
alphabet may prevent matrix recovery until the 
message itself is deciphered. In any case, both 
matrix recovery and analysis of the text follows the 
same techniques just explained. 


Section Ill. ANALYSIS OF PLAYFAIR CIPHERS 


11-7. (Q Rules of Encipherment 

a. In the analysis of Playfair cipher messages, the 
reconstruction of the enciphering matrix and the 
recovery of the plaintext are simultaneous and 
inseparable operations. This is due to the crypto- 
graphic nature of the system where both the cipher 
and plain values occur in the same matrix, being 
differentiated only by the rules of encipherment, 
and this differently in each specific case of digraphic 
encipherment. The rules of encipherment dictate 
the possible manner and combinations of placement 
of plaintext equivalencies in a given situation. 
Further, their specific placement determines their 
equivalencies in other combinations. Thus the two 
processes should be conducted as one. 

b. The relationship of the rules of encipherment 
upon the plain to cipher equivalencies, and their 
effect upon establishing the same values in the 


11-14 


process of recovery of the ciphertext is illustrated 
using the matrix shown in figure 11-25. 


Figure 11-25 (U). Example Playfair square i(7) 


(1) Where substitution involves letters at 
opposite ends of a rectangle, the following relution- 
ships exist as shown in figure 11-26. 


CONFIDENTIAL. 


CONFIDENTIAL — 


RECIPROCAL EVp = AZe 


REVERSIBLE AZp = EVe 


ed 
J 

Ul} 
N 
c~ 
Q 


GOp = IMe 
OGp = MIe 
IMp = GO0e 
MIp = 0Ge 
Figure 11-26 (C). Reciprocal reversible relationships (U). 


If the letters are assigned numbers as the possible 
combination shown here: 


12=34 
AZp=EVCO 
They may be expressed as an equation. Thus: 
Reciprocal 12=34 Reversible 
21=43 
Reciprocal 34=12 Reversible 
43=21 


(2) Where substitution involves letters of the 
same row or column these relationships may occur: 


12 34 
BCp=CDe 
CBp=DCe 
2143 


Note that in this case, only reversibility occurs and 
not reciprocity. That is: 


CDe does not equal BCp nor does 
DCe equal CBp 


(3) From the above it can be seen that in all 
cases, column, row, or rectangle (where 12=34), 
21=43. But only when 1 and 2 form appropriate 
diagonal corners of a rectangle does 34=12 and 
43=21. 


c. The position that a letter occupies in the Play- 
fair matrix coupled with the method of encipher- 
ment determines its limitation in combination with 
other letters, and consequently its equivalent value. 
Any given letter can be represented by eight other 
letters, the four occupying the same row and the 
four occupying the same column. 

(1) Thus, where encipherment occurs along a 
row or column, a given letter can be combined with 
only eight other letters, which can be further limited 
to four if the direction of encipherment is known. 

(2) In the case of encipherment involving a 
rectangle, the same letter can be combined with 16 
other letters, 8 of its own row and column plus the 
8 of the other letter forming the diagonally opposite 
corner. Where encipherment is along a row or 
column the letter may be combined with 8 other 
letters, 4 for the row and 4 for the column. Of the 
24 possible equations that can be formed by a given 
letter, as either the initial or final letters of a digraph, 
five will indicate a corresponding repetition of a 
given plaintext letter. 

d. The effect of the above observation is such to 
allow the formulation of certain rules in respect to 
the identification of digraphs produced by a Play- 
fair cipher. These rules are: 


(1) Rule 1. In all cases if 1.2=3.4 
then 2.1=4.3 

In case of rectangle if 1.2=3.4 

then 2.1=4.3 

then 3.4=1.2 

then 4.3=2.1 


(2) Rule 2. Where 1.2p=3.4c, for example 
ENp=CPe, there is a minimum probability of one 
in five that any other cipher digraph beginning with 
Ce has Ep as the initial letter of its corresponding 
plain digraph. Also, any cipher digraph which ends 
in Pc has the same probability of Np as the last 
letter of the corresponding plain digraph. 

(3) Rule 3. In those equations where 1.2p=3.4c, 
1 and 3 can never be identical, nor can 2 and 4 ever 
be identical. 

(4) Rule 4. In those equations 1.2p=3.4c where 
2 and 3 are identical, the letters are all in the same 
row or column, and in the relative order 1-2-4, 2 and 
3 in this case being synonymous. For example, in the 
matrix above, BCp=CDc. There are five cyclic 
permutations which will produce the proper se- 
quence. They are: 


11-15 


CONFIDENTIAL — 


(5) Rule 5. In an equation where 1.2p=3.4c and 
1 and 4 are identical, the letters are again in the row 
or column but in_the order 2-4-3. For example in 
the matrix above DCp= EDc; thus the order is CDE. 
The five possible cyclic permutations of this absolute 
order are: 


CDE-- 
DE--C 
E--CD 
--CDE 
-CDE- 


e. The importance of these rules are that they will 
allow the formulation of an assumption concerning 
the arrangement of values within the cipher matrix 
and the elimination of equivalencies in the crypto- 
gram. 

. Hxample: 

(1) Rule 1, where 1.2=3.4 and 2.1=4.3, gives 
rise to digraphic idiomorphs which may be used in 
the assumption of probable words. Thus the word 
ATTACK can be enciphered by the matrix in 
figure 11-25: 


AB BA 
P AT TACK 
C DQ QD EH ATp=De 


TAp=QDe 


(2) Rule 2, where the probability of similarity 
exists, indicates that once each common combination 
as ERp, ORp, and ENp have been assumed or 
determined, the rules can be used in discovering 
additional digraphs and partial words. 

(3) Rule 3, where 1 and 3, and 2 and 4 can never 
be identical, aids in the elimination of possibilities 
when a specific message is being studied. 


11-16 


(4) Rules 4 and 5 permit the establishment of 
values and their correct sequencing in the recovery 
of the matrix. 


11-8. (C) Analysis of Playfair Cipher 

a. To illustrate the steps and process involved in 
the solution of a Playfair cipher, the following 
example will be used. Assume that the analyst has 
previously identified the message as the product of 
a Playfair cipher on the basis that it contains an 
even number of letters, that repeats and spacings are 
multiples of two, that no doublets occur, that several 
letters are missing, and finally the discovery of what 
appears to be Playfair idiomorphs in the repeated 
sequence. Moreover, for the purpose of this illus- 
tration, it is assumed that the analyst has divided 
the plaintext into its digraphic units, prepared a 
frequency distribution, and tabulated significant 
repeated sequences, figure 11-27@ and 11-27@. 
With the preliminary studies completed, analysis 
may commence. 


123 4 5 6 7 6 91012 12 13:14 15 
A EC _OG EC UR RO VQ AD 2B FG MG AW CE WO DY AC 
B&Q QM CT MG KN RA AR IQ MG RB IR IK Wl KB CY 
C AR IQ MG YF UY UY BT LG UP EP ME FK BR AC KR 
D CY AR AH RA WA EM CI EC AW CE SW CE QE PO ME 
E EM VO ME LD CU QA PQ RE LQ UY GT TV PB XC QP 
F EA YF UY BN GO NC LD PK RF LZ CI DT KR EA QI 
G GT iV EC LF OR LR QA PQ AR BD LG QL OZ QI BN 
H CF TG FK DN CR FK GR PZ ZA AE GF DQ RG CY EQ 
I CW QU QF AL EC BS CI EM LU PC 


Figure 11-27@ (C). Ciphertert prepared for analysis (U). 


MS OD a 


Figure 11-27@ . Digraphic frequency distribution Playfair cipher (U). 


b. A close examination of the text reveals the 
following repeated sequences: 


Line B5 KN RA AR IQ MG 
B1i4-C3 KBCY AR IQ MG 
C15-D4 KR CY AR AH RA 
D14-E3 PO ME EMVO ME 
E6-G8 QA PQ 
E11-Gl GT TV 


(1). The first sequence, with its ABBA pattern 


suggests the word BATTALION... digraphically 


divided as: 


+B AT TA LI ON 

KN RA AR IQ MG 
If these values are correct, the second listed repeats 
may also be the same words, enciphered with an X 
between the TT doublet, divided as: 

BA TX TA LI ON 

KB CY AR IQ MG 


By using the values assumed in the first two se- 


quences, the third sequence equals: 


Tx Ts AT 
KR CY AR AH AR 


CONFIDENTIAL___ 11-17 


468-095 O- 72-11 


-~CONFIDENTIAL 


It is obvious that this sequence can hardly be 
“BATTALION,” but another common word in 
which the TT doublet occurs is “ATTACK.” If 
this is the correct _word_for the sequence, the 
CKp=AdHe and -Ap=KRe. 

(2) The repeats QA PQ, and GT.TV are sug- 
gestive of the word STOP. However, at this point, 
the assignment of plaintext values to either would 
be sheer guess work; therefore, for the moment 
they are bypassed. The values that have been 
assumed may now be inserted in the text and again 
studied for further exploitable patterns. On line 
B, immediately preceding the assumed word 
“BATTALION,” the digraph MGc is noted, which 
equals ONp. Aware that “BATTALION” is often 
preceded by a number, the possible ON p is suggestive 
of SECOND. The acceptance of this would permit 
the expansion of the sequenee to: 


-QM CT MG KN RA AR IQ MG 
-S EC ON DB AT TA LI ON 


If BATTALION in the first instance is preceded by a 
number, it is very likely to be the case in the second 
instance as well. From the fact that there normally 
are only three battalions to a regiment, the analyst 
may infer that either “FIRST” or “THIRD” 


probably is the second number. In dealing with 


numbers, one tends to keep them in order. Therefore, 
the word THIRD would be assumed. This sequence 
then can be expanded to: 


IR IK NM KB CY AR IQ MG 
-T HI RD BA TX TA LI ON 


Thus the remaining digraphs RB JR, may equate to 
the word “AND,” as 
RB IR 
AN DT 
c. Once a few values have been tentatively 
established, the analyst can, using the rules of en- 
cipherment discussed in the previous chapter, expand 
the values recovered. First a tabulation of all as- 
sumed values is made and, using rule 1 where 
1.2=3.4 then 2.1=4.3, the reversals are shown in 
figure 11-28. 


11-18 


Assumed Values Rule 1 Reversal 


=Sp = QMe ESp = Nae 
ECp = (Te CEp = TCe 
dip = Me Top = aie 
DBp = Rie BDp = WKe 
ATp = RAc TAp = ARe 
IIp = Ide Tip = Qe 
ANp = RBe NAp = BRe 
Dfp = Ike TDp = Ale 
Hip = [ke THp = Kie 
RDp = Mie DRp = Mle 
BAp = KBe ABp = BKke 
TXp = CYe XIp = Ye 
=Ap = KRe i=p = Fke 
CKp = Ate KCp = Hac 


Figure 11-28 (C). Use of rule 1 to determine plaintezt 
values (U). 


(1) The next step is to apply rules 4 and 5 to 
the above equations in order to recover possible 
row and column sequences of the enciphering matrix. 
Both lists are examined for equation of 1.2=3.4 
where 2 and 3, and 1 and 4 are identical. The follow- 
ing equations are noted. 


ECp=CTe BAp=KBe 
TAp=ARc 
LIp=I@e 
HIp=/Ke 


—CONFIDENFIAL—_ 


Rule 4 states that in the equation 1.2=3.4 where 2 
and 3 are identical, the relative order from left to 
right or top to bottom is 1-2-4. Thus the equations 
shown become: 
ECp+CTc=ECT 
TAp+ARc=TAR 
Lip+7Qe=LIQ 
Hip+7Ke=HIK 
Rule 5 states that in an equation 1.2=3.4 where 1 
and 4 are identical, the relative order is 2-4-3 from 
left to right or top to bottom. Then the equation 
BAp=ABc becomes ABK. 
(2) Note that only the assumed values are used. 
The values obtained by rule 1 could have been used 
equally as much. However, the results would have 
only been the reversal of what has been established. 
As a rule, in the beginning stages it is not wise to 
mix the two, as it tends to introduce too many 
possibilities of deriving the same value. Moreover, 
note that only the absolute order of a sequence is 
being used, not all of its permutations. At this 
stage, their introduction would again only result in 
confusion. As analysis continues, and if the ac- 
cepted absolute permutation is not consistent with 
the matrix dimensions and enciphering process ob- 
served, the other permutations can be used. 
(3). Examination of the sequences, noting their 
common letters, indicates that they can be chained, 
figure 11-29, to form a pseudo-matrix. 


Note that in each case the values that can be 
obtained are the same and that the sequential order 
of each sequence is maintained. Only their arrange- 
ment differs. 

(4) Using the pseudo-matrix the analyst can 
now scan the list of assumed values above in figure 
11-27 and add values to the pseudo-matrix, where 
required, to complete an equation. For cxample 
ANp=#Bc is noted, as well as its reversal 
NAp=BRe. With this the N can be placed as shown 
below. By continuing the same process, the equa- 
tions DTp=/Re, DBp=KNe, and RDp=VMe are 
located in the list and, once fitted, permit the expan- 
sion of the matrix as shown in figure 11-30. 


Figure 11-30 (ph. First expansion of matrix (U). 


ECT d. With a partially recovered matrix which will 
logically produce all the assumed values listed, it is 
TAR now possible to return to the text and attempt to 
break out further portions. With so few values it is 
LIQ not expected to produce any degree of intelligibility 
other than bits and parts. These again will be the 
HIK basis of further assumptions and consequent expan- 
ABK sion of the matrix. Following the partial decipher- 


ment of the message, the following significant 


Figure 11-29 p. Construction of preliminary matriz (U). passages are observed. 


0-15 KR CY AR AH RAWA EMCI EC AW CE SW CE QE 


A TX TA CK AT R— TH RE ER ER —T 
F-13 KR EA QIGT TV EC LF OR LR QA PQ 

—-A RT IL RE NT ST 
G-9 AR BD LG QL OZ QI BN 

TA NK it IL LB 


ERp is likely to be EZ to form ZERO. Logically 
expanding, the phrase shown below can be developed 
“ATTACK AT ZERO THREE ZERO ZERO.” 
With this phrase, the following cquations, figure 
11-31, can be developed and the matrix expanded 
as shown. 


(1) In each of the passages above, sufficient 
plaintext values are at hand to lend substance to 
good assumptions. The first phrase is obviously a 
time reference relating to the time of the planned 
attack. The plaintext bit THRE can only be a part 
of the word “THREE.” The digraph AWc preceding 


-GONFIDENTFIAL—_— 


11-19 


§ 
u 
= 
Q 


= 
Le] 

u 
g 
Q 


Olp = Swe 
Ofp = dEe 


Figure 11-31 (C). Second expansion of matriz (U). 


(2) The second phrase obviously consists of 
the words ARTILLERY REGIMENT, probably 


For example: 


followed by STOP. 


Fi3 KR EA QI GT TV EC LF OR LR QA PQ 


-A RT 


On this basis, the following equations can be pro- 
vuced, figure 11-32, and the matrix expanded again. 


GTe 


| 


RYp = TVe 


GIp = LFe 


Pac 


oO 
I 
" 


Figure 11-32 p. Third expansion of matriz (U). 


(3) The third phrase TANK UNITS WILL, 
where UNp=LGe provides the one additional value. 
Thus, the matrix is completed as shown in figure 
11-33. It is now a simple matter to decipher the cryp- 


togram. 


Figure 11-33 va Reconstructed Playfair matriz (U). 


11-20 


IL (LE)(RY) RE (GI)(ME) NT ST (OP) 


11-9. (Z) Completion of the matrix 

a. In“the preceding example, the proposition that 
recovery of the text and reconstruction of the matrix 
proceeds simultaneously is shown. The question yet 
to be answered is whether it is the correct matrix. 
The fact that a message can be deciphered does 
not prove its correctness. This condition arises 
out of the fact that for each specific matrix 
there are 24 additional cyclic permutations which 
will give exactly the same results. The importance 
of the recovery of the original matrix lies in the 
possibility of predicting future matrix values given 
the knowledge of current matrix arrangement. 

b. In the case of a keyword mixed sequence as the 
Playfair matrix, recovery of the permutation of the 
square presents little difficulty, using as a base the 
UVWXYZ cluster which rarely forms a part of 
the keyword. To observe this, examine again the 
matrix in figure 11-34, just previously recovered. 


Figure 11-34 q. Playfair matriz reconstructed (U). 


CONFIDENTIAL _ 


—GONFIDENTIAL _—_ 


The last three rows are obviously out of sequence, 
V should precede the W, M should precede the 0, 
and D should precede the F. By a simple shift of the 
last column to the first position, the matrix is 
reordered and now in its correct sequence. This can 
be noted in the appearance of the keyword REC- 
TANGULAR. This is a simplified example, but it 
serves to illustrate the point that in keyword mixed 
sequences, the alphabetic sequence of that part of 
the alphabet outside the keyword sequence serves to 
reorder the matrix. Other cases are more complicated, 
but the basic principles remain the same. 

c. In the case of Playfair matrices based on a 
transposition mixed sequence, the recovery of the 
original presents a different problem for which 
different procedures must be used. Essentially the 
process lies in the recognition of patterns in one of 
the original matrix’s permutations and, using this as 
a base, reconstructing the original. The following 
illustrates this process. 

(1) Given an original matrix, shown in figure 
11-35, recovery of a transposition mixed sequence 
and the keyword follows the same procedures as 
previously given for transposition ciphers. 


[a [e |w lela 


Figure 11-36 (f). Playfair matriz (U). 


By scanning the rows of the matrix, which correspond 
to the columns of the keyword matrix, several bits 
which exhibit alphabetic progression can be found 
They are: AGW, LDV, FMZ, PBU, and YEN. ~et 
on end as columns and juxtaposed in alphabetic 
sequence by last letter, they form the order: 


PL AY oF 
BDGKM 
UVWXZ 


With this, the beginning of the keyword should be 
obvious, leading to a rapid solution. But if it wus 
not, by shifting to the second row and building 
further on its sequential pattern, the following 
sequence would be produced, as shown in figure 
11-36. 


-CONFIDENTIAL — 


S716 h 6:9 2-53 
PLAYFIRCEHE 
BDGKMUNOQST 
UVWX Z@ 


Figure 11-36 (C). Recovery of mized keyword sequence (U). 


(2) Where the analyst works from a permuta- 
tion of the original enciphering matrix, a modifica- 
tion in this procedure is required as a preliminary 
step. He must first find some one permutation which 
shows the sequence characteristics on which he can 
base the recovery of the keyword. For example, 
given the matrix permutation of figure 11-37, 
recovery of the keyword would be difficult, as its 
rows do not exhibit columnar order of the transposi- 
tion matrix to the required degree. 


Figure 11-37 ip. Matriz permutation (U). 


Since a permutation of the rows does not affect 
keyword recovery, the analyst need only permutate 
the columns. This can be done by constructing a 
5 x 9 matrix of repeated columns, as illustrated 
in figure 11-38. 


Figure 11-38 p. Repetition of column permutations (U). 


11-21 


GONFIDENTIAL 


(3) Testing each five by five combination, the From this permutation using the underlined se- 
analyst will soon find a permutation containing the quences, the original keyword and matrix can be 
appropriate sequence. In this case, it is the fifth, recovered as illustrated in figure 11-40. 


shown in figure 11-39. 
87609391452 


POLYGRAEHIC 
BODEFKMNQST 


UVWX a 


Keyword: POLYGRAPHIC 


/ Figure 11-40 . Recovery of keyword mized sequence and 
Figure 11-39 (Q). Selection of correct permutation (U). original enciphering matriz (U). 


11-22 CONFIDENTIAL 


PART FIVE (£f 
POLYALPHABETIC SUBSTITUTION SYSTEMS 


CHAPTER 12 ¢€) 
PERIODIC POLY ALPHABETIC SUBSTITUTION 


Section |. (Cf INTRODUCTION 


12-1. (Sf Meno- and Polyalphabetic Cipher 
Systems 

a. In previous paragraphs, the cipher systems 
presented used one basic alphabet for the encipher- 
ment of messages. Thus they are classified as mono- 
alphabetic ciphers. It is true that certain of those 
systems provide for variant values, yet they are not 
classified as polyalphabetic. The essential difference 
between monoalphabetic and polyalphabetic substi- 
tution lies in the primary objective of the system. 

(1) In- those monoalphabetic substitution sys- 
tems having variant values, the object is to suppress 
so far as possible the characteristic frequency of 
letters and resultant word patterns. Several methods 
are shown, some which provide several - different 
cipher values as equivalents for all the plaintext 
letters, and others which provide only variant values 
as cipher equivalents for the high-frequency letters. 
In each system there are conditions inherent in the 
method of encipherment itself, conditions that 
produce, in the cryptogram, certain definite clues 
that lead to the establishment of the equivalencies 
for one plaintext value. 

(2) Moreover, each of those systems derives its 
security from the care with which the cryptographer 
performs his task. Given the free choice of using 
variant values, or if he was hurried or slip-shod and 
used the same variant value consistently, he would 
materially detract from the security of the system. 

(3) In either case, the end result is that crypto- 


grams are produced whose true security lies in the 


minimum use of the system. Given a number of 
cryptograms from the same system, or a few com- 
bined with poor encryption procedures, solution is 
relatively easy. 

b. In the case of true polyalphabetic substitution 
systems, the object is to establish a definite proce- 
dure for the automatic shifting or changing of a 
number of cipher alphabets employed in the en- 
cipherment of a single message during its encipher- 
ment, thus producing variant values. Furthermore, 
this method, within certain limits, is bevond the 
whim of the cryptographer. The total result of such 


‘a system is to greatly increase the degree of difficulty 


in establishing the cipher equivalencies of a given 
plaintext value. There are a number of true poly- 
alphabetic cipher systems, although for nulitary their 
number is limited for reasons of practicality. All 
true polyalphabetic systems will exhibit following 
essential characteristics. 

(1) Each plaintext letter is represented by two 
or more cipher equivalents, their exact identities 
being determined by the position they occupy in the 
plaintext. 

(2) One and the same cipher letter represents 
two or more different plaintext letters. the exact 
equivalencies being determined by the system itself. 


12-2. (27 Example of Polyalphabetic Substitu- 
tion 
a. Polyalphabetic substitution is illustrated in 
figure 12-1. 


GCONFIDENTIAL—_. 12-1 


-GONFIDENTIAL — 


P ABCDEFGHIJKLMNOPQRSTUVWXY2Z 


Cl 
ce 
C3 
ch 
C5 
C6 

Key: L2345 62234 
ENEMY REENF 
GVTTC IGMCM 
61 23456123 
Ea PS Or ee 
ZP DXJIMEKBWN 
1234 5612 3 
ZERO ZERO WN 
BMGV DVTW C 
345612 3456 
ATTACK INDI 
PAXRES XUHZ 
GVTTC IGMCM 
DXJIJME KBWNVd 
CPRVR WHZMS 
LHXXX 


[¢ [De lr [Gla|rie{x[L[Miw solr la iRis |r lu[v |W [xy |Z || 6 | 
I id |x IL Wi olPleiRis|riul vw ix] yi2 4 [Bc [D| 
PIQ\R|S PiU Vil xi ¥[zlafBl cl Ole RIG lary [x] LIM ji] O| 
PHIT 7 [xk [L[ Mw] olPl@yR siti ul Vw] xi y [Zale ic [Dle | P| | 
PEF IG|HIT| J] K/L Mw olPlaiR|s| ri Ul Vv iw) x) ¥ [ZA [eB ICID 
LAI |r ju |v) W] x{¥[ 2) A} 8] Cc] oO] BPG] a) Te} x] 2 [ew] [Phe | 


62,.2°3°4:5.61 2345 
RCEMENTS SEEN 
IEMBLRKU ATLR 

45 6123 456 

OF HILL ONE 

VJ YKTA VRYV 

56 12345612 

NE POSSIBLE 

RV RWHZMSWNU 

2345 

ATED 

PILE 

SIEMB LRKUA TLRZP 
YKTAV RVBMG VDVTW 
NMPAX RES XU HZETII 


Figure 12-1 fp. Example, polyalphabetic substitution (U). 


b. In the system above, the cipher equivalent for 
the first plaintext value is drawn from the first cipher 
component (Ep=Gc), the second from the second 
(Np=Ve), and so forth until the sixth cipher com- 
ponent is reached. At this point, the seventh letter of 
the message, the first cipher component, is used once 
again as the source of the cipher equivalency. Thus 
the frequency of the plaintext letter and any charac- 


teristic pattern that might occur in the plaintext 
are suppressed. 

c. The method of encipherment demonstrated 
above can be duplicated with a simple strip arrange- 


ment and a numeric key which corresponds to the 
different juxtaposition of the cipher and plain 
sequence above. For example, the alphabet could be 


reproduced as follows: 


P ABCDEFGHIJKLMNOPQRSTUVWX YZ 
C ABCDEFGHIJKLMNOPQRSTUVW XYZABCDEFGHIJKLMNOPQRS | vtec. 


(1) In figure 12-1, the successive juxtapositions 
of the plain to cipher are Ap=Cel, Ice2, Pc3, He4, 
Ec5, and Rc6. These juxtapositions can be indicated 
by the assignment of numeric values to each. Thus, 
they may be indicated as 3-9-16-8-5-18, where 3 
indicates the third letter of the cipher sequence (c), 
9 indicates the ninth letter in the cipher sequence (1), 
and so forth. These numbers indicating the sequen- 
tial position of the letters are the cyclic setting of 
the strip. 


(2) To encipher the message given above. the 
keys can be written out horizontally and thu message 
inscribed in column beneath the key. The strip 
alphabet is set at its first key setting (3). 
Ap=Cc and all letters below this key are cnciphered. 


where 


The setting is then changed to the next key, 9. when 
Ap=Ie and all letters below this key are enciphered. 
The same process is continued until the entire 


message is enciphered; then it is transferred to five- 


12-8 —CONFIDENTIAL— 


GONFIDENHAL—— 


letter groups. A partial example is shown below in 
figure 12-2 using the same data as ‘in figure 12-1. 


3 9 16 &8 5 18 
EON EM YX RB 
Qe 
B :E re 10) 

Gua cus £ 
Cc iu N T 
EM oBLR xk 
s § EE OF I 
uA TER 2 


Ciphertext : GVITC IGMCM SIEMB LRKUA TLRZ. ... etc. 


Figure 12-2 fi. Columnar encipherment duplicating key 
period (U). 


12-3. (& Classification of Polyalphabetic Sub- 
stitution Systems 

a. Polyalphabetic substitution ciphers can be 
classed into two distinct types, periodic systems and 
aperiodic systems. The periodic systems include 
those whose cryptographic treatment results in 
the production of cyclic phenomena in the crypto- 
graphic text. Note, for example, the columnar 
encryption process just demonstrated. Therein, 
the cyclic nature of periodic polyalphabetie substi- 
tution can be seen in the repetition of constant plain 


to cipher equivalencies in each column, i.e. in the 


first column Ep=Ge, in the second, Ep=Me, in 
the third Ep=Tc, and in the fourth Ep=Le. 
The cryptographic process of aperiodic systems on 
the other hand is designed to eliminate this cyclic 
phenomena. The specifics of this system and its 
analysis are treated in chapter 14. 

b. The cyclic phenomena inherent to a periodic 
system may be exhibited externally, as in the 
system above. In these cases, the phenomena is 
said to be patent. In some ciphers the cyclic phe- 
nomena is not exhibited in the cryptographic text, 
in which case they are said to be latent. The periodic- 
ity of the cipher under these conditions must be 
uncovered by a step to be explained, preliminary to 
analysis. 

(1) The periodicity of a given system may be 
quite definite, determinable with mathematical 
preciseness, in which case the periodicity is said to 
be fixed. The example above fits this definition, the 
period there being fixed at six. 

(2) In other instances, the periodicity may be 
more or less flexible, depending upon the system, 
but subject to definite limits imposed by that 
system. In such a case the periodicity is said to be 
flexible. 


c. A primary classification of periodic systems is 
by the number and method of usage of the cipher 
alphabets. All periodic systems are considered to be 
either a repeating key or a progressive alphabet 
system. 

. (1) In a repeating key system, only a few of a 
whole possible set of cipher alphabets are used in 
enciphering a given message. These alphabets used 
in a fixed sequence determined by the key are em- 
ployed repeatedly until the message is enciphered. 
Possibly the same key may be used to eneipher a 
second message, or a new key may be used for cach 
message. The key itself may be a seeret word, a 
phrase, or a number. In any case, it determines the 
numbers, identity, and sequence of use of the cipher 
alphabets. 

(2) In a progressive alphabet system, all the 
cipher alphabets comprising the complete set for the 
system are used one after the other, in turn. for the 
encipherment of » message. When the last alphabet 
is used, the sequence of use is begun anew. 


12-4, (2) Classification of Cipher Alphabets 

a. The substitution process in polyalphabetic ci- 
phers involves the use of a number of alphabets 
which can be derived by a number of methods. The 
exact nature of their preparation, which determines 
their characteristics, plays an important role in the 
solution of polyalphabetic ciphers. Cipher alphabets 
for polyalphabetic substitution are classified as 
independent and derived. 

(1) Independent or unrelated cipher alphabets 
contain separate and distinct plain and cipher 
sequences having no relationship to one another. 
Such sequences can be derived by any of the methods 
previously discussed, i.e. they may be keyword 
mixed columnar, keyed columnar mixed, or deci- 
mated alphabets. The solution of cryptograms pro- 
duced with independent alphabets is made more 
difficult by the very reason that no relationship 
exists between them. For this reason, in the course 
of analysis, values are not transferable. However, 
since their production and handling in the erypto- 
graphic process poses problems affecting their prac- 
ticability, they are not as favored as interrelated 
cipher alphabets. Hence, they are not as often 
encountered. 

(2) Derived or interrelated alphabets, as the 
names imply, are produced by the interaction of 
two primary components which, when juxtaposed at 
various points, yield a number of secondary alpha- 
bets. The number of secondary alphabets, given 
two constant primary components, is equal to the 
number of different points of coincidence. In effect 
then, what is brought about is either a strip system, 
such as the one shown in paragraph 12-2c, or a 


-CONFIDENTHIAL—__ 12-3 


CONFIDENTIAL — 


cipher alphabet, also shown in paragraph 12-2a, 
which has one plain component and several cipher 
sequences, all of like structure, joined together at 
varying points of coincidence. The cipher sequences 
generated by the juxtaposition are termed secondary 
alphabets. : 

6. For the purpose of cryptanalysis, some of the 
more common configurations of the primary com- 
ponents and secondary alphabets derived therefrom 
are given in the following: 

(1) Case I. The primary components are both 
normal sequences. 

(a) The sequences proceed in the same direc- 
tion; the secondary alphabets produced are direct 
standard alphabets offset at points of juxtaposition. 

(6) The sequences proceed in opposite direc- 
tions; the secondary alphabets are reversed standard 

‘alphabets and are reciprocal with the same limita- 
tions as discussed in paragraph 7-6a. 
(2) Case II. The primary components are not 
both normal alphabets. 

(a) The plain component is a standard 
alphabet and the cipher component is a mixed 
sequence; the secondary alphabets are then mixed 
alphabets. 

(6) The plain component is a mixed alphabet 
and the cipher component is a normal alphabet; the 
secondary alphabets are again mixed alphabets. 

(8) Case III. Both components’ are mixed 
sequences. 

(a) Components are identical mixed sequen- 
ces proceeding in the same direction; the secondary 
alphabets are also mixed sequences. 

(b) Components are identical mixed sequen- 
ces proceeding in opposite directions; the secondary 
alphabets are mixed sequences and also are recipro- 
cal, again with the limitations discussed in paragraph 7-6a. 


Ok=Ai 
(i) 


(c) Components are different mixed sequences 
either proceeding in the same or opposite directions: 
the secondary alphabets are mixed alphabets. 


12-5. (Q Repeating Key 

a. It4s the use of a repeating key which imparts 
the cyclic pattern, or periodicity, to periodic poly- 
alphabetic substitution. Repeating keys are used to 
indicate the number, identity, and the sequence of 
the cipher alphabets used. The key itself, as shown 
in preceding examples, can be expressed in terms of 
numbers or letters, both derived from the other. 
and the letters usually spelling out a word. The 
literal key may be a word, a phrase, or even a sen- 
tence, usually being easily recalled. 

b. In the key proper, its total number of elements 
determine the number of alphabets to be used. The 
identity of each element determines the specific 
cipher alphabet used, and its relative order in the 
key determines the sequence of the cipher alphabets. 
The total number of cipher alphabets available for 
use in a given system may be unlimited, except for 
practical purposes. However, where alphabets ure 
reproduced by sliding two primary alphabets against 
one another, only 25 cipher alphabets, in the case of 
English alphabets, are possible. The key then, in 
some respects, is unlimited as to length. However, 
in rhost cases it will be found to correspond to a 
word, phrase, or sentence, usually one that is easily 
remembered. 

c. To use a key in finding equivalents with sliding 
primary components, four elements must be known. 
They are the key letter (k), the index letter (i), the 
plaintext letter (p), and the cipher letter (c). 

(1) The key letter and the index letters indicate 
the point of coincidence of the cipher and plain 
component. For example: 


P ABCDEFGHIJKLMNOPQRSTUVWX YZ 
C ABCDEFGHIJKELMNOPQRSTUVWXYZABCDEFGHIJKLMNOPQRSTUVWAYZ 


(k) 


(2) The meanings associated previously with ¢ 
and p remain unchanged, ¢ indicating the cipher 
value and p the plaintext value. Thus to find one 
value, an equation using these elements may be 
written as: 


Ok=Ai; Ep=Se 
(3) Note that in the above, two tacit assump- 
tions are involved. First it is accepted that the index 


letter (i) is found in the plain component and that 
it is the letter A, and second that the key letter (k) 


12~4 


is found in the cipher component. Normally this is 
the case. However, it need not be so. The index 
letter used, and the relative location of k,i. p, and ¢ 
can be easily changed, only a fixed agreement between 
the correspondents being required. Thus in a key 
and equivalency equation, the key and index letter 
must be specified and the relative location of all 
elements shown. This can be accomplished very 
simply, merely by adding a number (1) for the plain 
component, and (2) for the cipher component to the 


GONFIDENTIAL_ 


CONFIDENTIAL =~ 


equation given above. Thus the conventional method 
of ‘finding an equivalency is shown as: 


Ok/2=Ai/1; Ep/1=Se/2 


(4) As mentioned previously, the normal method 


of finding equivalencies need not always be followed. 
In fact, employing 2 sliding components and the 
4-element equation, 12 possible combinations result. 
However, as the method above is most widely used, 
only it will be given. 


Section Il. (2) THEORY OF SOLUTION OF PERIODIC POLYALPHABETIC SUBSTITUTION 


12-6. (Dh The Three Steps of Analysis 

a. The cryptography of periodic polyalphabetic 
substitution, as illustrated previously, is such that 
its solution may be effected by the completion of 
three steps in succession. These steps are: 

(1) Determining the period. The analyst at- 
tempts to determine the length of the key which 
imparts the cyclic periodicity to the system. This is 
done through the isolation and analysis of groups 
found repeated in the message. The repeats used in 
this approach must not be accidental repeats, but 
repeats which have resulted through a cyclic juxta- 
position of similar sequences in the plaintext and 
similar sequential periods of key usage. In effect, 
the determination of the period identifies the num- 
ber of alphabets used in the system as the cyclic 
periodicity is a result of the use of a number of 
alphabets. 

. (2) Reduction to monoalphabetic terms. In this 
step, once the period has been identified, the analyst 
can divide the text into a number of segments 
equal to the number of alphabets involved, each of 
these segments representing that portion of the 
ciphertext produced by one of the cipher sequences. 
Thus a polyalphabetic text is reduced to its mono- 
alphabetic bits and is susceptible to analysis on 
those terms. 

(3) Identification of ciphertext values. The third 
step is that of analyzing each of the monoalphabetic 
ciphertext distributions produced by the second 
step in order to determine their respective plaintext 
values. In this step, essentially the same techniques 
are used as for the analysis of any monoalphabctic 
cipher. 

b. The foregoing steps comprise the general out- 
line of solution for any periodic polyalphabetic 
substitution cipher systems, regardless of the kind 
of cipher alphabets involved. There is, of course, 
some modification required for each particular casc. 

c. As a matter of course, prior to the analysis, 
any cryptosystem must first be identified. Identifica- 
tion, in the case of periodic polyalphabetic substitu- 
tion cipher systems, rests upon the two character- 
istics of the system, its polyalphabeticity which 
imparts a relative flatness to the frequency distri- 
bution, and the cyclic phenomena within the text. 
Statistically, computations will indicate that the 


message text is random. The cyclic use of a number 
of alphabets will result in cyclic phenomena indi- 
cated by one or more of the following conditions: 

(1) Length of message and repeats will not be 
divisible by a constant factor. 

(2) Distance between repeats will be a factor 
of the period length. 

(3) Small cyclic periods, particularly those of 
even numbers, are apt to produce significantly 
higher than random digraphic indexes of coincidence. 

(4) Statistical computation of each monoalpha- 
betic sequence, the result of step two, usually 
indicates plaintext, though this is subject to varia- 
tion due to relative numbers of letters enciphered 
by each sequence. 


19-7. LEF Basis for Determining the Period 


. a. The external phenomena on which the deter- 
mination of a system’s periodicity is based, is a 
result of the encipherment of an identical plaintext 
letter by the same cipher sequence, several times. 
The repetitions so produced are called casual 
repetitions since their cause is a direct result of the 
use of a periodically repeating key. It also happens 
that different plaintext letters, enciphered by a 
different cipher sequence, will produce identical 
cipher letters in the ciphertext. In this case, since 
the repetitions are produced by the accidental 
juxtaposition of different values, they are termed 
accidental repetitions. 

b. As the determination of the period length 
depends upon the analysis of repetition which occurs 
in the ciphertext, it is obvious that a distinction 
must be made between causal and accidental repe~ 
titions. In the case of single letters, this becomes 
very difficult as accidental repetitions can occur as 
frequently as causal repetitions. Thus no basis for 
distinguishing one from the other is provided. 
However, in the case of digraphs and polygraphs, 
the chances of a number of different plaintext letters 
and cipher sequences coinciding sequentially several 
times to produce accidental repetitions of ciphertext 
is greatly reduced. Statistically, the chances of 
repetitions of varying length occurring in a given 
number of letters of random text can be computed. 
Thus the repetitive phenomenon which may be 


—CONFIDENTIAL — | 12-5 


GONFIDENTIAL 


expected as a result of pure chance can be duplicated, 
and pre .ides a means of evaluating the significance 
of repetitions observed in a ciphertext. If the 


observed repetitions are no more than would be 
expected by chance, generally they would not be 
considered significant. However, if the repetitions 
exceed the value of chance repetitions, they would 


be open to interpretation and exploitation as causal 
repetitions. 

c. A summary of the expected number of appear- 
ances of digraphs, trigraphs, tetragraphs, and penta- 
graphs in samples of random text of 100 to 1000 
letters, in increments of 100 is shown in figure 
12-8. 


Number 
of 
letters 


100 
200 


400 


letters 


OOOO 0O00CO00 


Expected number of digraphs occurring exactly x times 


Number Number Number 
of of of 
letters letters 


POOOCCOO0CO00 


oOocoocoocoo°co 


Figure 12-3 g. Table of expected polygraphs (U). 


The numbers in columns E(2), E(3), etc., refer to 
the numbers of times a given number of digraphs can 
be expected to occur by chance in the sampling of 
letters given in the column at the left margin. Thus 
in a sample of 300 letters of random text, i.e. periodic 
polyalphabetic substitution, 43 digraphs can be 
expected to appear twice, 6 digraphs can be expected 
to appear 3 times, and 1 digraph can be expected 
to appear 4 times. The decimal fractions that 
follow in the succeeding columns of the same row 
may be interpreted as follows: the value 0.683 under 
column E(4) means that in 100 samples of 300 letters 
each, about 68 of them will have a digraph which 
occurs 4 times; 0.060 under column E(5) indicates 


that in 100 samples of 300 random letters, 6 samples 
will contain a digraph occurring 5 times. Thus in the 
tables, the number within the brackets indicates the 
number of polygraphs, and the number in’ each 
column below that symbol indicates the number of 
times of their occurrence in a message or messages. 


12-8. 4) Determining Periodicity 

a. Using the statistical information contained in 
the foregoing table, the determination of periodicity 
of a cryptogram is a relatively simple matter. As an 
illustration, the following cryptogram shown in 
figure 12-4 with repeated groups underlined, will 


be used. 


12-6 CONFIDENTIAL 


CONFIDENTIAL— 


5 10 15 20 25 
A -USYES ECPMP_LCCLN XBWCS OXUVD 
D  SCRHT HXIPL IBCIJ USYEE GURDP 


(C AYBCX OFPJW JEMGP XVEUE LEJYQ 


D MUSCX JYMSG LLETA LEDEC GBMFI 


Figure 12-4 (C). Ciphertext with evidence of periodicity (U). 


b. In the message above, the observed repetitions 
are far in excess of those normally expected. For 
example, 7 digraphs are observed being repeated 
twice (EC, PL, SC, BC, JY, US, and CX), about 
the expected values for a message of 100 letters. 
However, note that 2 other digraphs (LE and US) 
are repeated 3 times, a rate of repetition expected 
in the case of a message of 200 letters. Finally, the 
repeat of the tetragraph (USYE), statistically 


expected in a random text message of 1000 letters, 
establishes almost beyond any doubt that the repeats 
are causal rather than accidental. The only explana- 
tion is that the plaintext value for USYE must fall 
in exactly the same relative position to the key in 
both instances. 


12-9, (2) Factoring To Determine Length of the 


Period 

a, Since periodicity, as reflected in causal repeti- 
tions, is a result of enciphering identical letters by 
identical cipher sequences, it follows that the 
length of the period can be ascertained by determin- 
ing the constant interval between repeated occur- 
rences of the same digraph or polygraph. For ex- 
ample, by counting the letters intervening between 
each repeat, the count to include the letters of the 
first but not the second appearance of the repeat, 
the following intervals and factors will be found 
(fig. 12-5). 


lst USYE to 2d USYE 
ist BC to 2d BC 

Ist CX to 2d Cx 

ist EC to 2d EC 

lst 

ed LE to 3d LE 

ist LE to 3d LE 

lst JY to ed JY 

ist PL to 2d PL 

1st SC to 2d SC 


vow 


VUMNMNM MW MWMND NP 


> 
> 
> 
3 


(lst SY to 2d SY, already included in USYL.) 
(Ist US to 2d US, already included in USYE.) 


2d US to 3d US. 
ist US to 3d US 


(lst YE to 2d YE, already included in USYL.) 


Figure 12-6 p). List of repetitions and factors (U). 


b. After determining the interval between all 
repetitions, each in turn is factored, the object here 
being to locate one factor which is common to all. 
Recall that a given key length, synonymous with 
the number of cipher sequences, determines the 
periodicity of a system. Further, note that any given 
causal repetition occurs as the result of the enci- 
pherment of a group of identical letters by the same 
key sequence. Now this may occur at the first, sec- 
ond, third, etc., cycle of key usage. In any case, it 
must be a permutation of a fixed number, the key 
length. Therefore, factoring the intervals should 
reveal the true key length. Similarly, if one or more 


intervals are found which cannot be factored by 
some number as the majority of the intervals, they 
can be assumed to be accidental repetitions. With 
this in mind, examine the factors given in figure 
12-5. 

ce. It will be noted that with the exception of 
CX, all the repetitions can, be factored by either 2 
or 4. In the case of CX, since its factor is both differ- 
ent and isolated, its repetition can be ascribed to 
accidental rather than causal reasons and can, 
therefore, be dropped from further study. Thus only 
the factors 2 and 4 are left for consideration. Since 
these factors are common to all intervals between 


—CONFIDENTIAL, 197 


CONFIDENTIAL— 


repetitions and since the repetitions have been 
determined to be causal rather than accidental, the 
key length, or number of cipher alphabets, must be 
one or the other of these numbers. 

d. In this particular case, the final choice for the 
key length cannot be resolved except by reducing 
the ciphertext to its monoalphabetic components. 
However, on the basis of practicability, it can be 
assumed that the key length is four rather than two. 
In cases of multiples it is better to assume the larger 
number initially. 


12-10. ( Reduction to Monoalphabetic Terms 


a. In foregoing paragraphs, the inherent mono- 
alphabeticity of segments of a periodic polyalpha- 
betic cipher are demonstrated. As this monoalpha- 


USYE SECP MPLC 
HTHX IPLI BCIJ 
FPJW JEMG PXVE 
GLLE TALE DECG BMFI 


b. Each group above represents the periodic cycle 
of the cipher sequence. Thus all first letters of each 
group are produced by the first cipher alphabet, 
the second letter by the second alphabet, and so 
forth. With the monoalphabetic segment of the 
ciphertext now isolated, a separate uniliteral fre- 
quency distribution is made for each. Theoretically, 
if each distribution is great enough, and contains 
no abnormal variation from common usage, each 
frequency distribution should result in the charac- 


beticity arises from the cyclic encipherment of the 
plaintext by a fixed number of alphabets, a poly- 
alphabetic ciphertext can be reduced to mono- 
alphabetic terms when it is divided into segments 
by a number which corresponds to the key length. 
The division of the ciphertext can be accomplished 
by either setting the message down in columnar 
form, each column representing the use of one 
enciphering alphabet, or by transcribing the message 
into groups equal in length to the key. Each group 
then represents one periodic cycle of cipher alphabet 
usage. In either case, the results are the same, the 
choice of method left to the analyst. Using the 
latter method the example message would be 
transcribed as: 


CLNX BWCS OXUV DSCR 
USYE EGUR DPAY BCXO 
UELE JYQM USCX JYMS 


teristic peaks and troughs of monoalphabetic sub- 
stitution. Under normal circumstances, where the 
correct period has been determined, this occurs 
and seems to prove the correctness of the assump- 
tion of period lengths. However in more difficult 
cases, where the sample is small, and contains an 
insufficient number of polygraphic repetitions, or 
where a clear cut choice between two possible factors 
of periods cannot be made, other monoalphabetic 
substitution tests may be used. 


Section Ill. (4) STATISTICAL TEST FOR DETERMINING PERIODICITY 


12-11. The Phi (¢) Test 


a. The monoalphabetic ¢ test, previously dis- 
cussed in paragraph 2-15, may be applied to the 
distribution of periodic polyalphabetic ciphers to 
confirm the monoalphabeticity of the distribution 
made on the assumption of a given period. This test 
is particularly applicable in difficult cases where each 
distribution is noncommittal in respect to peaks and 
troughs, as where the factoring process results in the 
choice of two possible period lengths. When the 
correct period is assumed, then the ¢ test of each 
distribution should approach fairly closely and con- 
sistently the values for @p. On the other hand, if an 
incorrect period is assumed, the calculated go should 
approximate the value of gr rather than ¢p. 

b. To illustrate this process, ¢o of the distributions 
made of the example cryptogram is calculated in 
figure 12-6 using the formula ¢o=Zf(f—1). 


N25 


A BCDEFGHIJKLMNOPQRST UVWXY2Z 
ol2o06000006000000000012Z00000 
dp = .0667N(N-1) = 40.02 o = f£(f-1) = 36 
dr = .0385N(N-1) = 23.10 
N-25 
ABCD EFGHIJSKLMNO PQR STUVWXYZ 
0020120000002 00012 00120000220 
dp = .0667H(N-1) =. 40.02 go = $f(f-1) = 4b 
gr * .0385N(N-1) = 23.10 
{1-25 
AB CDEFGHISJK LMNOPQRSTUVWXY2Z 
o02e000000002 200000002 00020 
dp = .0667N(N-1) = 40.02 go = Sf(f-1) = 46 
dr = .0385N(N-1) = 23.10 
i-25 
ABCD EFGHIJKLMNOPQRSTUVWXYZ 
0000 30 ao202000000002 20000600 f(f-1) 
fp = .0667N(N-1) = 4o.02 do = Sf(f-1) = kb 
Or = .0385N(N-1) = 23.10 


Figure 12-6 (C). The @ test for factored periods (U). 


12-0 ~GONFIDENTIAL— 


-CONFIDENTIAL— 


c. In this case, the results of the ¢ test are indica- 
tions that each alphabet represents a case of mono- 
alphabetic substitution, which in turn proves the 
validity of the original determination of the cipher’s 
period. Note that in some cases a @ test conducted 
on the multiple of a true period will result in the 
appearance of monoalphabeticity. An example occurs 
in this particular case where, if eight was assumed, 
the resultant distribution and their ¢ tests indicate 
monoalphabeticity. However, an inspection of the 
distribution reveals that on the basis of similar 
characteristics distributions 1 and 5, 2 and 6, 3 and 7, 
and 4 and 8, could be combined into 4. Whatever 
the method used, the result is the same, the reduction 
of the ciphertext to monoalphabetic terms. 


12-12. (QJ The Index of Coincidence (I.C.) 


a. Another method of proving the apparent valid- 
ity of the factoring process is through the use of the 
index of coincidence. The I.C. was previously defined 
as the ratio of ¢o to @r, expressed in formula as 


LC, =$9-The monographic I.C. of English plaintext 


is 1.73 as compared with the I.C. of 1.00 for random 
text. Using this text, the individual distributions, if 
the factoring process is correct, will tend to conform 
more closely to the expected I.C. of plaintext than 
to the IC. of random text. 

_b. To demonstrate the operation of the formula 
and show its results for comparison with those 
obtained by the ¢ test, the foregoing distributions 
and the calculated values of ¢o and gr will be used 


(fig. 12-7). 


Ic for Distribution No. 1 1.00 IC of English Random Test 
2 = IC or 36 = 1.56 
ir 23 1.73 IC of English Plain Text 
Ic for Distribution Ne. 2 1.90 IC of English Random Text 
rE - ICor bb = 1.91 ; 
r 23.1 1.73 IC of Englisa Plain Text 
Ic for Distribution io. 3 2.00 IC of English Random Text 
@ = TC or &6 = 1.99 
ir 23.1 1.73 IC of English Plain Text 
IC for Distribution Jo. 4& 1,06 IC of Fnelish Pandom Text 
jo = IC or 44 = 1.92 
or 23.10 1.73 IC of Fnrlish Plain Text 


Figure 12-7 (@). Index of coincidence for factored periods (U). 


c. In all four cases above, it can be seen that the 
I.C. calculated for each distribution more closely 
approximates the LC. of plaintext than that of 
random text. Thus, as in the case of the ¢ test. the 
results, ie. the monoalphabeticity of each cdistribu- 
tion is indicated, further indicate that the initial 
assumption of a period of four is correct. 


12-13. (J Table of Expected Values 


As an aid in the calculation of either monographic 
L.C. or @ values, a table of the expected values of op 
and ¢r for sample sizes from 11 to 100 is given below 
in figure 12-8. To use the table (fig. 12-8), only the 
value of N, the total number of letters occurring in 
a given distribution, need be tabulated and the values 
of ¢o determined. 


Figure 12-8 O. Expected values of gr and op (U). 


-CONFIDENTIAL — 12-9 


CONFIDENTIAL 


12-14, Kot Statistical Tests to Determine Peri- 
odicity 

a. A variation of the ¢ test may be used for the 
initial determination of periodicity, as opposed to 
proving a prior assumption as illustrated above. This 
particular method is quite useful in those cases where 
the length of the period is long as compared to 
ciphertext length, and where there is no pronounced 
repetition pattern in the text itself. For example, 


i 1 2 
2 0 > 0 

HSKUSPMPHDUSJSJIXMSPTPO 
BOOGAOPGPRHBOUCSHPVGH 
TU KREKVWZXVLISFHWARLKFI 
FCSKTGOOYBXZVLISZRYACD 
EXPYPQHDNOJIXNZTGHUDO 
TDVEVLETDOAFROUNYWNBDY 
KKZITPHKRTICCOASBZUGBU 
KZ 7 
bh O20 2 28: 002 OOO OS ko ee 


Figure 12-9 ( 


(2) To compute the go, the normal formula is 
used, ie. go=Zf(f—1). Note that in the diagram 
above, there are 2 columnar lengths; one of 8 letters 
(2 columns) and the other of 7.letters (38 columns), 
which must be kept separate. This data contained in 
the diagram is then tabulated as shown below. The 
column labeled ¢ is the observed value of ¢ from the 
table above. The column labeled x is the number of 
times the particular @ value occurred, and @x is the 
product of the two columns ¢ and x. 


Columns Columns 
N=8 N=7 

% | x ox fo) x xX 
0 1 0 0 | 17 0 
2 1 2 2/19 38 
4 1 4 
2 2 6 1 | 1 
38 43 


(3) Having derived the $x value by tabulating 
the data as shown above, it then can be used to 
determine the average value of @ (symbolized by 
¢, which is read as Phi Bar). This is done using the 
formula p=ox for each N value. The average value 

x 


12-10 


given the cryptogram below where the length of the 
key is between 40 and 50, it can be treated as shown. 

(1) First, an arbitrary key length is selected and 
the eryptogram is written.out horizontally to conform 
to that width. Selecting a key width of 40, the 
ciphertext is inscribed as follows in figure 12-9 and 
the goZf(f—1), of each column is computed, using 


only repeated letters. 


2 3 3 \ 

5 0 5 0 
IPCIWKZVUYPPNEUSATIG 
QXKEZSACKRKVBGHHVSFRY 
JSLGMHRARQOTUVT XE UE C 
WETJUSCAFPIEZAXKOKAQIUN 
ARFUERJOYEBDOKEITKDGY 
QOBEGGSHQUKOPUYZCOCYH 
BBUNOVTPOVMIZDEPQFY 
20000220020 20:20:62 02 


. Computation of oo long periodic key (U). 


of @ (@) is derived by adding up all the $x values 
for a given column length, and then dividing by 
the number of occurrences of columns of that 
length. Thus @ for the above are: 


N= N=7 
Gate ey pet ie 

x <2 38 

o=1 $= 1.16 


(4) For comparison purposes, the value of or 
and @p must be computed using the formulas: 


op=0.0667N(N-1) or 0.0667 x Sx 7=3.73 
ar=0.0885N(N~1) or 0.0885 x 8 x 7=2.15 
and 
op=0.0667N(N-1) or 0.0667 x 7 x 6=2.80 
or=0.0385N(N-1) or 0.0385x 7x 6=1.61 


The information now is set up in a table for com- 
parison purposes as shown below: 


N=8 N=7 
Observed @ 1.00 @ 1.16 
Expected plain 9p 3.73 gp 2.80 
Expected random gr 2.15 gr 1.61 


(5) On the basis of the comparison above, a 
key width of 40 is rejected. The next step then is to 
assume another key length, reinscribe the message 
to that width, and recompute all values again. 
This same process is repeated until a good match 
is attained. In this specific case the process would 


GONFIDENTIAL— 


CONFIDENTIAL — 


be repeated until a width of 43 was reached. The in figure 12-10. 
computation at this point would appear as shown 


HSKUSPMPHDUSTTIXKUSPTPOITPCIWKZVUYPPNEUSATITGBOO 
GAOPGPRHBOUCSHPVGHQKZSACKRKVBGHMVSFRYTTRKHKY 
WZ2XVELITHWARLKPISSUTUHKAHQTUVIXSHECFCSKTPGOOY 
BXZVLISRYACDWETHSCAFPIEAXOKAQDWEKXPYPQHDi OUI 
XNZIGNUDOARFUERZTOYBDOKEIKDUVTDVEVLETUOAKRROU 
NYWNBDVQOBEGGSHQHXOPUZTCOCUKKZTTPHKRTCCOASBTE 
GBUBBUNOVTPOVMIZDEPQFVK2 i 
20244 e2Ee6h 02424604044 62048 2204204 2224024 62 
Figure 12-10 (@. go long periodic key computation (U). 
(6) Again the average value of @ (@) is com- given, and the derived data is set forth in tabular 
puted, as are gr and 9p, using the formulas previously form as below: 
Columns Columns 
N=7> N=6 
@| x | ox | @| x | @x | 
0 | 4) 0 0) 3 0 | 
2}; 6 | 12 2! 9 18 
4| 1 | 46 | 4] 4 | 16 | 
6 | 3 | 18 p= =F = 3.08 6] 1 6 
24. ~«74 ? eee i 
4} 1 14} Gao 28? 23 96 
19 62 Br ke 
N=7 N=6 
Observed $ | 3. 08 | | 3. 26 
= 
Expected plain op | 2.80 | | 2.00 
— ! 
Expected random or | 1.66 | | 1.15 
b. The results of the last test leave little doubt application of the same test. However, in those cases 
that the key length of the cipher is 43. Consequently, where the key is long, or where no repeats occur in 
analysis is based on that assumption. Obviously this the text to indicate key length, it is an effective tool. 


process is rather involved in terms of repeated 


-GONFIDENTIAL- 12-11 


468-095 O- 72 - 12 


CHAPTER 13 (€f 
SOLUTION OF PERIODIC POLYALPHABETIC SUBSTITUTION SYSTEMS 


Section I. (@f SYSTEMS USING STANDARD CIPHER ALPHABETS 


13-1. (CJ Determination of 
Alphabet 


a. Once a given periodic polyalphabetic cipher 
has been reduced to monoalphabetic terms, the 
question arises as to what type cipher alphabet is 
involved. This should be determined in the initial 
stage of analysis as it directly affects the techniques 
employed, and moreover, determines the relative 
difficulty of the task of recovering plaintext. values. 

6. In practice, the type cipher alphabet used in 
a given system may be one of the forms given in 
paragraph 12-4 preceding. As the cipher letters, of 
themselves, give no hint of the exact form used, the 
analyst must determine this. As in the case of normal 
monoalphabetic substitution ciphers, a uniliteral 
frequency. distribution may be used for this deter- 
mination. Such a frequency distribution made of 
each factored segment, given sufficient depth for 
each, will usually indicate whether the cipher alpha- 
bets involved are standard (direct or reversed) or 
mixed. 

c. In some cases only two or three distributions 
are necessary for the initial determination of the 
type cipher alphabet involved. However, for subse- 
quent analysis a distribution must be made for 
each. Additionally, if the alphabet appears to be a 
mixed cipher alphabet, then it is helpful for subse- 
quent analysis to prepare triliteral frequency distri- 
butions for each. Note that because of the reduced 
size of the distribution, the characteristics which 
permit the identification of the type alphabet may 
not be as pronounced as those given in previous 
examples. However, if one takes into consideration 
the reduced size of the sample, identification can 
usually be made. 

d. Once the identification of the alphabets in- 
volved has been made, an analysis of each to deter- 
mine their plaintext values can begin. Basically the 
techniques involved are similar to those previously 
explained for the analysis of monoalphabetic substi- 
tution ciphers. There is one difference which arises 
out of the use of several cipher alphabets which 
may or may not be related, and which therefore 


Type Cipher 


permits the use of an additional method. Generally, 
although the actual analysis may be more involved, 
it is dificult only in those cases where a reduced 
depth of material is encountered. The difficulty 
stems from the lack of data, not from its complexity. 
However, where messages are long, or where several 
messages have been enciphered in the same kev, 
each distribution should contain sufficient elements 
to permit a ready identification of ciphertext values. 


13-2. (CX Preliminary Identification and Factor- 
ing 
a. Using the principles for analysis set forth in the 
preceding chapter, a eryptogram is prepared in the 
normal manner as illustrated in figure 13-1. 
5 : 10 15° “20 25 
A AUKBY JAMKI SYUWN JUIGK BPULE 


8B ETIMI ZHBHR AYHKZH IFLVME SJKUTGE 


C DPVXK QUKHQ LHVRE FALZNHG GEVKE 
D NLUFM PZIJNV CHUAS HKQGK IPLWP 
E AZZXI_ GUNTV OPTES ECMYS QYBAY 
F ALAHY POIXW PVNYE EYXEE UDPKR 


G BVZVI 2@FfIFVO SPTEG KVUBBRF QLLKP 


H WFQGK NILLE PTIKW OD éxI GoOror 
J ZLAMV KFHWF NPLZI OVVFRNR OKTKG 
K NLMDF AAEXI JLUEFU Pei NV CAIGI 


L UAWPR WVIWE JKZAS GLAFM HS 


Figure 13-1 (C). Ciphertext prepared for analysis (U). 


b. After the cryptogram is set down, it is Inspected 
for repeated sequences, and those found are under- 
lined as shown. In this particular case where a num- 
ber of trigraphs and polygraphs are repeated, it is 
not necessary to bother with the digraphs. The reason 
for.this can be understood if reference is made to the 
table of expectancy in paragraph 12-7c. In this 
message of.271 groups, five trigraphs are observed 
occurring twice each, better than twice that expected. 
Moreover, the odds for the observed recurrence of 


~GONFIDENTIAL— 13-1 


the pentagraph is on the or 


-GONFIDENTIAL — 


der of 1 in 50. The point . 


is that these repetitions would almost certainly be 
causal rather than accidental und therefore could be 


used for factoring to determ 


ine the period of the key. 


c. On this basis the repetitions may be set down 
in tabular form with their locations, interval, and 
factors for study as shown below. 


Repetition Location 


Interval 


Factors 


Repetition Location Interval Factors 
QGK D18, H3 85 3, 17 
UKH A2, C7 35 3,11 
ZLA Ji, L16 65 3, 18 


d. Only the briefest inspection of the list of factors 
is required to reach the assumption that the period 
length is five. This being the case, a uniliteral 
frequency distribution is made of the text at an 


LUFMPZJNVC D2, K12 160 2, 4, 5, 8, 10, 16, 20, interval of five. Note that it is not necessary to 
32, 40, 80 seri : o ae 
JXIG £2, H17 WO. Bea a6 00s tacae retranscribe the text when group rength; or its 
30, 43 multiple, corresponds to assumed key length. Ac- 
EJK B20, L10 215 5, 43 cordingly, the following distributions would be 
PTE El2, G12 50 2, 5, 10, 25 produced (fig. 13-2). 
(1) Distribution 1. 
Zi sS= Ben Ze 2Z_ZE -~ = z= 
ABCDEFGHI JKLM NO PQRSTUVWXY Z@ N = 55 
S 3-23-30 32-2. 62:10 62 5:30 2:0 2-0:.2 0 0.6 
2002660622 30200 3002060002000 0 30 do = 164 
dr = 114 gp 2198 Ic = 1.4h 
(2) Distribution 2. 
= — 
2 1. = B-=sEBZ. =2 ~=22 £#F 
ABCDEFGHIJSI kK L MNO PQRST U VWX YZ N = 55 
5011030312 4910250012 4 koo 4&3 
2000006060212 72 002200002 1212001264 pp = 184 
dr = 114 dp = 198 Ic =1.61 
(3) Distribution 3. 
—— = Z=-= = Z_ —_— = = =27__ Zz 
ABCDEFGH IJK L MNOPQRST U VWXY 2Z@ N= 54 
33002000 822 4 81012003 4 5110 5 
66000000 562212560002006 1220000 20 po = 200 
r=110 $0 = 190 Ic=1.8 
(4) Distribution 4. 
ABCDE F G HISKLEUMNOPQRSTUV WX Y 2 N= 5h 
321013 4 4 400223311010202 4 9 2 2 
606061212420 0:-2:2.6.6:0 00'0.0'2:0-2 12 72 2-2 do = 174 
gr =110 $p=190 Ic = 1.58 
(5) Distribution 5. 
Z— = Z = 2 —~= == Z#o== 
ABCD EF GH IJKL MNOPQ RSTU VWXYZ N= 54 
0000 62 409130 70121 4300 52220 
0000 30212072060%42002012600202220 do = 210 
gr =110 dp =190 I¢=1.91 
Figure 13-2 B. Uniliteral frequency distribution of ciphertext on period of five (U). 
13-8 CONFIDENTIAL — 


“CONFIDENTIAL — 
13-3. (C) Fitting the Distribution to the Normal tion are suppressed, a closer inspection reveals their 
a. The statistical tests completed show that each prOSEnCE, and shows that they are distributed 
distribution is apparently plaintext, exhibiting the linearly rather than being bunched; an indication 
expected characteristics of monoalphabetic substi- that the sequences are standard rather than mixed. 
tution and thereby proving the assumption of a Mie ee BY eae es ee ek ee. Bt 
period ob'tive. “This eine’ dhe dese; dhévnext logical em to the normal by the usual process of locating 


ide on tactars anton xed decd high frequency equivalencies. 
step is to determine Ha mixed or standard sequence 6. By noting the relative distances between the 


was used. If the latter, the solution would be greatly peaks and troughs and their trend, ie. direct or 
simplified by a determination of the point of coin- reversed of distribution 1, it appears that We= Ap. 
cidence between the plain and cipher sequences Note that at this point of coincidence the normally 
which would establish all equivalent values. Al- expected high frequency plaintext letters conform 
though the peaks and troughs of the above distribu- to the high frequency cipher letters thusly: 

P ABCDEFGHIJKLM™MNOPQRS TUVWXYZ 

C WX YZABCDEFGHIJSJIKLILMNOPQRS TUYVY 


Continuing the same process of comparison of the 
peaks and troughs of each cipher sequence with P ABCDEFGHIJKLMNOPQRSTUYWKYE 
that expected for plaintext, it becomes apparent ae ag ae 
that the remaining points of coincidence are: 
Distribution 2 Ap=Hc 
Distribution 3 Ap=lTIe 
Distribution 4 Ap=Te 
Distribution 5 Ap=Ee 
c. At this point it is obvious that the KEY is 
WHITE and that the arrangement of the several 
sequences is as shown in figure 13-3. . Figure 13-3 (OX Recovered enciphering matriz (CU). 


The text then may be deciphered to read: 
ENCOUNTERED RED INFANTRY ESTIMATED AT ONE 
REGIMENT AND MACHINE GUN COMPANY IN TRUCKS 
NEAR EMMITSBURG(.) AM HOLDING MIDDLECREEK NEAR 
HILL FIVE FOUR THREE SOUTHWEST OF FAIRPLAY(.) 
WHEN FORCED BACK WILL CONTINUE DELAYING REDS 
AT MARSH CREEK(.) HAVE DESTROYED BRIDGES ON 
MIDDLECREEK BETWEEN EMMITSBURG TANEYTOWN 
ROAD AND RHODES MILL(.) 


13-4. (2 Completing the Plain Component cipher sequence, solution is also possible. but slightly 
different techniques are required. 

b. In respect to the solution of periodic polyalpha- 
betic ciphers by this method, there is one difference 
based upon the number of generatrices. In mono- 
alphabetic, only one generatrix, that is. the cipher 
sequence, was used constantly throughout. In the 
case of periodic polyalphabetic systems there are of 
course several generatrices involved, each used at a 
constant interval in a fixed sequential order deter- 
mined by the period of the key. Thus a shghtly 
different approach is required. If for example the 


a. As in the case of monoalphabetic substitution 
where direct standard sequences are used, so too can 
periodic polyalphabetic substitution systems, if using 
direct standard sequences, be solved by completing 
the plain component. The underlying principle in 
the latter case is the same, i.e. the cipher sequences 
are nothing more than direct standard sequences 
offset as numbers of positions. Thus by simply 
inscribing a direct standard sequence vertically below 
each cipher letter using it as a point of origin, a 
columnar matrix is developed in which one line of 


plaintext appears. Note that as in the case of simple former method was used it would be quite difficult 
monoalphabetic substitution, but using either a to pick out the individual generatrices. This is shown 
reversed standard cipher sequence or a known mixed in figure 13-4 below, where the plain component was 


_CONFIDENTIAL— 1343 


NK HES CHANADWOVORESONYHROWDMAOUNw Pe 
—HaNDWDOVO SEO ARUHHROQAMOAQWPNK HK RG 
GHMOWMVUAWPNK NH ES CHANWOVIS ZEA 
OAMOQWENhK KES CHHNDWOHVOAROAYGVHM 
SHES CHYHNDOHVOBSZOARAGHHROAMONQU PNK 
HMQODMMOQWPNK HES CHNWMHOVOS 


PAS 


— 
oo 


NK XM ES CHNDOVOR SM AGCHHBADAHM UAW 
PAUHMADMHONOW PNK HK EM CHHNWOVO SK 
GHMOAAONAW PNK KH ES CHNDWHVOBAEOAN 
DOW OAWrPNKH ESCH NWOVO BAS AYH 
KRXM ES CHNDOVISBSROAGVHMADAAONQW PN 


SESCHNWOVOSZS ESPADA MADD AW PNK 
ONHHMABMWMOQWPRP NHN ET CHNWOVIOAS 
SCHON WDDODVOS ZORRO DPEVAWPEPNK SKS 

SHMORAOTADPNK KH ESS CHANDWHOHVOAE 
HrOQOQAAMOAQTD PNK HK SS CHNWOVOBRROAN 


2 


4 


AATIAWPNKH KHER CHANWO VOSS ZerNuHma 
HSCHAWOVO RS RONGVH RADHA OUAWPN« eK 
MUOAWPNKHKH RA GCHAWOVOARAZORYHDMAY 
PAGDHMODMOUAMD PNK KR ES CHHNWAVOASE 
AUHMmaADAAUAQWPNK HRS CHNWOH VOSA Rh 
Bt CHANWDOVOBRSSZSYPAUHAMAYAMOQAW PN 


ROAWKAHMAMAOANW PNK KEMAH HNAWHOVOA 


OAKHAM OMMUOWP NKR REAM CHNDWOWO 
TOMA CAWDPNKHKH RESCH NDWOVWVO SRA UWH 


Figure 13-4 (GY). Completion of the plain component (U). 


13-4 


woonrnaw FPwn br 


Alphabet 1 


AJZJNEZALTS 


. Alphabet 2 


UAYMFTHYLK 


completed for the first 25 letters of the foregoing 
eryptogram. 

c. With the prior knowledge of the period (5), and 
the plaintext, it is possible to pick out plaintext from 
the matrix above, but even so it would be a difficult 
task. Where the period or plaintext were not known 
it would he practically impossible. Thus it is neces- 
sary to first separate the ciphertext into its individual 
generatrices. Now this will of course result in the 
factoring of the plaintext at a constant interval, that 
of the period length. So the question of how plaintext 
would be recognized is posed. The answer to this lies 
in the association of high-frequency letters normal 
to plaintext. Each correct generatrix will normally 
contain a greater and better assortment of high- 
frequency letters than the other generatrices and 
thus is distinguishable. To reconstitute the plaintext, 
the selected generatrices are reordered according to 
their order of appearance in the ciphertext. To show 
this process, the example cryptograms will again be 
used. In this instance the first 50 letters, decimated 
at the period of five, is set down in columnar form. 
each column conforming to the use of one cipher 


alphabet as shown in figure 13-5. 


LA 


BRAKOFABJK 
CLBLPGBCKL 
DMCMQHUCDLM 
ENDNRIDEMN 
FOEOSSEFNO 
GPFPTKFGOP 
HQGQULGHPQ 
IRHRVMHIQR 
JSISWNITRS 
KTITXOSKST 
LUKUYPKLTU 
MVLVZQLMUV 
NWMWARMNVW 
OXNXBSNOWX 
PYOYCTOPXY 
QZPZDUPQYZ 
RAQAEVGRZA 
SBRBFWRSAB 
TCSCGXSTBC 
UDTDHYTUCD 
VEUEIZUVDE 
WEVEJAVWEF 
XGWGKBWXFG 
YHXHLCXYGH 
ZIYIMDY ZHI 


Figure 138-6 ( 


_ VBZNGUIZML 
WCAOHVJANM 
XDBPIWKBON 
YECQIXLCPO 
ZFDRKYMDQP 
AGESLZNERQ 
BHFTMAOFSR 
CIGUNBPGTS 
DJHVOCQHUT 
EKIWPDRIVU 
FIT XQESTWV 
GMKYRFTKXW 
HNLZSGULYX 
IOMATHVMZY 
JPNBUIWNAZ 
KQOCVSXOBA 
LRPDWKYPCB 
MSQEXLZQDC 
NTRFYMARED 


OUSGZNBSFE 


PVTHAOCTGF 
QWUIBPDUHG 
RXVICQEVIH 
SYWKDRFWIT 
TEXLESGXKS 


Alphabet 3 Alphabet 4 Alphabet 5 
KMMIMIBMVU HKWGLMHZMT YIMKXXIRMEG 
INWNINIJCNWV =ILXHMNIANU ZI NYYISNFH 
MOOKOKDOXW oJMYINOJBOV AKOZZKTOGI 
NPPLPLEPYX  KN&ZJOPKCPW BLPAALUPHS 
OQQMQMFQZY  LOAKPQLDQX  CMQBBLIVQIK 
PRRNRNGRAZ MPBLQRMERY DNRCCNWRd L 
QSSOSOHSBA NQCIURSNFSZ EOSDDOXSKi 
RITPIPITCB ORDNSTOGTA FPTEEPYTLIN 
SUUQUQJUDC  PSEOTUPHUB GQUFFQZUMO 
TVVRVRKVED = QTFPUVQIVC HRVGGRAVNP 
UWWSWSLWFE RUGQVWRIWD ISWHHSBWOG 
VXXTXTMXGF = SVHRWXSKXE JTAITITCKPR 
WYYUYUNYHG  TWISXYTLYF KUYJJUDYQS 
XZZVZVOZIH UXITY ZUMZG LVZKKVEZRT 
YAAWAWPAJI VYKUZAVNAH  MWALLWFASU 
ZBBXBXQBKJ  WZLVABWOBI NXBIMXGBTV 
ACCYCYRCLK  XAMWBCXPCT OYCNNYHCUW 
BODZDZSDML YBNXCDYQDK PZDOOZIDVX 
CEEAEATENM ZCOYDEZREL QAEPPAJEWY 
DFFBFBUFON ADPZEFASEM RBFQQBKFXZ 
EGGCGCVGPO BEQAFGBIGN  SCGRRCLGYA 
FHHDHDWHQP CFRBGHCUKO TDHSSDMHZB 
GIITEIEXIRQ DGSCHIDVIP UEITTENIAC 
RJJFIFYISR ERTDIJEWSQ VF JUUFOJSBD 
IKKGKGZKTS FIUEJKFXKR WGKVVGPKCE 
JOILHLHALUT GJIVFKLGYLS XHLWWHQLDF 


CONFIDENTIAL — 


. Completion of the plain component, text arranged by period (U). 


-CONFIDENTIAL— 


When the high-frequency generatrices underlined tion. For example, the generatrices of alphabet 1 
above are set down in columns, the now consecutive shown crossed out in figure 13-6 could be dropped. 
letters of intelligible plaintext are readily recog- 
nizable. oe Gen. ALPHABET 1 
io Bea e ALPHABET 
5 2019 8 23 GENERATRIX Ll A-d-8-d-H-B-3-A-Z-o 
ENCOU 2 B~X-A-K-0-F-A-B-d-K 
NTERE 3 CLBLPGBCKIEI 
DREDI 4 DMCHMQHCDL# 
NFANT >) ENDNRIDEUN 
RYEST 6 FOEROQS JE FRO 
I MATE 7 GPFPITKFGOP 
DATON 8 H-@~-6-@-U-£-G-H-P-@ 
EREGI 9 ITRHRVUHIQR 
MENTA 10 d-8-4-S8-W-H-2-J-#-8 
NDMAC 11 Kk~P-g-F-X-0-d-K-8-F 
12 £~Y~K-Y-¥-P-K-£-F-9 
13-5. (2 Selection of Generatrices 23 M-Y-£-Y-2-Q-£-H-§-¥ 
a. The foregoing demonstrates how quickly a 14 NWMWARHWNY W 
solution may be reached using this technique once 15 9-#-H-x- B~S-H-O-W- x 
the system has been identified and the period deter- 16 sae a Oe ie Oe a Oe a4 Y 
mined. However, the real key to the solution lies in 17 Q-2-P-3-D-U-P-@-¥-8 
the selection of the correct generatrix from each 18 R-A-@-A-#-¥-@-H-3-A 
alphabetic column. As shown, it was selected on the 19 SBRBFWRSAB 
basis of the appearance of high-frequency letters in 20 TCSCGXSTBC 
the generatrix. Another method of selection may be res eae eae ae ge oe 
used which involves a more systematic approach 22 VEUEIZUVOE 
than mere visual inspection, again using frequency 23 WPRVFGIAYV W foe 
characteristics of plaintext. The probability of the ak i-G-W-G-K-B-W-d-F ad 
low-frequency letters J, K, Q, X, and Z appearing 25 ¥-H-X-H-£-6-H-¥- 6-H 
two or more times in a given generatrix is unlikely 26 g-2-¥-42-4-D-¥-2-H-F 
so they may be immediately dropped from considera- Figure 13-6 5. . Generatrizx identification (U). 


—~GONFIDENTIAL— 13-5 


CONFIDENFIAL- 


Gen. ALPHABET 1 SUM TOTALS 
1 A-d-t-d-N-8-2-A-i-d 
2 B-K-A-K-6-F-A-B-d-K 
3 CLBEBLPGBCKEI 0 
4 DMCHQHCODLM 0 
5 ENDNRIDEMN 7 
6 FOEOSJUEFNO T 
7 GPFPTKFGOP e 
8 H-@-6-@-U-2£-G-H-P-@ 
9 ITRHRVMHAHI QR 5 
10 o-S-i-S8-W-H-£-d-8-S 
il ~$-d-P-X-0-d-K-S8-F 
12 £-U-K-U-¥-P-K-£-F-9 
13 M-Y¥-L-¥-3-Q-£-H-9-¥ 
14 NWMWARMNVW iF 
15 6-X-H-X-B-S8-A-O-W-xX 
16 PYOYCTOPXY 3 
17 @-2-P-3-D-U-P-@-¥-4 
18 R-A-@-A-B-¥-@-8-2-A 
19 SBRBFWRSAB 5 
20 TCSCGKSTBC 4 
al UDTDAYTUCD 2 
22 VEUETITZUVDE 4 
23 WFVFIJAVWEF 2 
2k x-G~W-G-K-B-W-x-F-¢ 
25 ¥-H-X-H-2-6-X-¥-G-H 
26 g-2£-¥-L-H-D-¥-3-H-F 
Figure 13-7 oy Generatriz identification using arbitrary 
values (U). 
ABCDEFGHIJIKL) 
8 47 79 6 5 7 8 12 7 


b. These values are based on the relative fre- 
quency of each letter in telegraphic text and there- 
fore are especially effective where the generatrix 
contains very few values. The procedure for testing 
the probability of the correct generatrix is essen- 
tially the same as that given in the preceding 
example. A portion of the ciphertext sufficient in 
size to produce recognizable plaintext is decimated 
to form a base composed of the cipher values of one 
period. A column of generatrices is then produced 
by completing the plain component. Each generatrix 
of that column then is tested by summing the total 
values assigned to each of its letters by the values 
shown above. The generatrix then showing the highest 
total value is considered the best probability. Upon 
the selection of a generatrix from each plain compo- 
nent column, the letters are juxtaposed at the inter- 
val corresponding to the period to produce plaintext. 
Of course where doubt exists between several 
generatrices they may be played against each other 
to determine the correct one to use. 


13-6 


oo A 


6 


b. The choice of generatrices is now considerably 
lessened by the elimination of the generatrices lined 
through. The choice can now be further reduced by 
assigning an arbitrary value of 1 to each of the 
normal high-frequency letters E TN ROATIS and 
¢ to all others. By summing the values, an indication 
of the correct generatrix is then given. For an example 
of this note, figure 13-7. 


The choice of either generatrix 5 or 6 is obvious. 
The exact determination of which to use is made by 
u comparison of generatrices selected by the same 
process from the other plain component columns. 


13-6. (B Logarithmic Test for Generatrix Selec- 
tion 
a. A somewhat more precise method of determin- 
ing the correct sequence by measurement may be 
arrived at by using the logarithmic weights of plain 
English reproduced below: 


A 


OPQRSTU 
8 6 2 8 8 9 6 


o <J 


wxX Y Z 
5 6 0 


, 


w 


ce. A modification of this system and the one 
preceding it is to combine the two tests. The first, 
which is much quicker, may be used to initially 
select those generatrices which are easy to identify 
because of their own make up of letters. This test 
then can be used to select one generatrix from those 
previously isolated which would not be readily 
identifiable by the simpler method. 


13-7. Theory of Probable Word Method 


a. The probable word method, similar to that used 
in monoalphabetic substitution, may be used to 
effect a solution where the foregoing methods are 
of no avail, or where there is an insufficiency of 
external evidence to indicate the number of alphabets 
involved. This method is predicated on the use of a 
plaintext word or words as the cryptographic key 
and may be used when standard or known mixed 
alphabets are used. 

b. Essentially the method consists of assuming 
the presence of a word in the text of the message. 


CONFIDENTIAL _ 


-CONFIDENTIAL— 


The word is then fitted in turn at various positions 
in the message. At each point a plain and cipher 
sequence is juxtaposed to produce the observed 
cipher values. If the probable word is correct and 
is placed in the correct position of the message, the 


key letters produced by the juxtaposed plain and 


cipher sequences will yield a plaintext keyword. To 
demonstrate the theory of the solution, the follow- 
ing short message will be used. 


PGSGG DNRUH VMBGR YOUUC WMSGL VTQDO 


c. Assuming that the word REGIMENT appears 
in the above cipher and that it was produced using 
reversed standard alphabets, it may be set down as 
follows: 

(1) The plaintext is set beneath the ciphertext 
as shown to the right: 


(i) 
P ABCDEFGHIJK 
C GFEDCBAZYXW 
(k) 


Thus for the first equivalency the key letter shown 


as 


P@SG@GGDNR 
REGIMENT 
(2) Using two sliding strips, one direct as the 
plain sequence, the other reversed as the cipher 
sequence, they are juxtaposed so as to produce the 
equivalent cipher-plaintext values shown. 


NOPQRSTUVWXYZ 
TS RQPONMLKJII4 


below is produced: 


C PGS GGoODNR 
P REGIMEN T 


K G 


(3) The same two strips are now repositioned to 


P 

Cc KJtIHGFED 
C PGS GG@GoODNR 
P REGIMENT 
K GK 


(4) The same process is continued for each 
letter until all the key letters are determined. A 
continuation of the process will result in the following: 


C P@GSGGODNR 
P REGIMENT 
K GKYOS HAK 


Obviously the key so produced does not result in an 
intelligible word so the assumed word is shifted one 
position to the right relative to the text and the 


PGS GG@GODNRUHVMBG 


ri 


d. It should be noted that the key is a cyclic 
permutation of BUNKER HILL. Since the key- 
word or phrase repeats itself during the encipher- 
ment of a message it will appear periodically through- 
out the message determined by the position of the 
probable word in the text. Thus the keyword may 
well appear as a cyclic permutation, complete or in 
part. 


where Ep=Ge, and the second key letter derived. 


ABCDEFGHIJKLM™MNOPQRSTUVWRY Z 
CBAZYXWVUTSRQPONML 


process repeated. This trial, using the same sliding 
strips juxtaposed as appropriate, results in: 
C GSGG@G4DNR CO 
P REGIMEN T 
K XWMOPREN 
(5) Again an intelligible keyword is not pro- 
duced; therefore continue to shift the probable word 
to the right, one letter at a time. each time deriving 
n possible key. When the point of juxtaposition 
shown below is reached, a keyword becomes evident. 


"“OWUCWMSGZLVTRYDO 


13-8. (Z) Application of the Probable Word 
Method 


a. In actual practice the application follows some- 
what different lines. Using the previous example 
this can be seen in the following. First the message 
is written horizontally on cross-section paper and 
the probable word is written in a column. one space 
below and to the left of the ciphertext as shown in 
figure 13-8. 


CONFIDENTIAL— 1347 


GONFIDENFIAL- 


PGSGGDNRVUHVMBGRYOVUUCWHSGLVTQDO 


Figure 13-8 (p. Location of probable word (U). 


b. If the probable word assumed does exist in 
the message it may be located beginning at any one 
of the positions indicated by an x in the matrix 
above. Rp being the equivalent of the cipher value 
appears in the text directly above that point. 
Moreover, the remaining letters of the probable 
word are represented by the cipher letter to the right of 
that point. Thus if the key is a plaintext word or a 
phrase it will appear long the diagonal line, as this 
diagonal represents the successive encipherment of 
the probable word. The possible cyclic permutations 
of the keyword can be noted in the diagonal arrange- 
ment of the x’s. 

_¢. Again two alphabetic strips, one direct, and 

one reversed, to correspond with the .previous 
assumption that a reversed standard alphabet is 
involved, are used. However, since we have assumed 
that a plaintext word or phrase is being used as a 
keyword, it is not necessary to derive the key letter 
of each juxtaposition. Only the amount needed to 
prove the unacceptability of the relative location of 
the probable word to a position in the ciphertext is 
required. This being predicated on the proposition 
that an incorrect position and the consequent deriva- 
tion of key letters will produce impossible combina- 
tions of letters for a keyword. With this in mind, 
the strip may be juxtaposed and the keys shown in 
figure 13-9 below derived. 


PGSGGONRUHVMBGRYOVUCWMSGLVTQUO 


. Figure 18-9 (G). Key derivation (U). 


d. Examination of the trigraphs occurring along 
the diagonal, produced by successive juxtaposition 
of the two sequences, reveals several which may 
represent a portion of a keyword. For example, note 
the trigraphs EVA, LLB, XVE, ICU, PSA, LYT, and 
TAS which appear on the basis of vowel-consonant 
combinations to represent part of a possible keyword. 
However, it is also important to remember that 
seemingly improbable combinations, due to cyclic 
permutation, may well be the true keyword as in the 
case of the trigraph LLB appearing under UC above. 
At this point the analyst needs only to complete 
those diagonals which show possibilities of containing 
a keyword, again finding the same keyword. This is 
illustrated in figure 13-10. 

PGSGGDNRUHVHBGRYOUVUCWHSGLVYTEecG 


s[x|T PIFILIL] Tis, clay | 


pe DG ESE an aE 
jataiwizt if it 
| slyly Glaja]w ik ons 
dxleluiatalticistyimep i. ° 


tt — 


at 


Figure 13-10 ). Key derivation, step 2 (U). 


e. Once the keyword has been found, solution is a 
simple matter, for the process of determining the 
keyword has of itself proved the assumption concern- 
ing the structure of the alphabet used. In this case a 
matrix is constructed containing one standard 
alphabet as the plain component and seven reversed 
standard alphabets as the cipher sequence juxta- 
posed to form the keyword BUNKER HILI| below 
A of the plain. With this, the ciphertext can be 
deciphered to read: 


“MOVE YOUR REGIMENT TO RJ FIVE 
TWO SIX.” 

f. In the foregoing a whole cryptogram was used 
for example purposes. However, the technique may 
be applied to a portion of a longer cryptogram. In 
this case only a few prerequisites are required. First. 
a reasonably accurate probable word, then an idea 
of where this word is located in the message. Then, 
by trial and error as shown above, the keyword can 
be derived. Further, although the example above 
used a reversed standard cipher sequence, the method 
is equally applicable to cases where a direct standard 
sequence is used, and also when a mixed sequence is 
used, if it is a known sequence, and the repeating 
key begins under Ap. 


13-8 “CONFIDENTIAL _ 


_ CONFIDENTIAL —— 


Section Il. (@) SYSTEMS USING MIXED CIPHER ALPHABETS 


13-9. (& Characteristics of Mixed Alphabets 


a. Polyalphabetic systems which use standard 
alphabets as cipher and plain sequences, because of 
their inherent simplicity, are not widely used. The 
reason for their vulnerability to analysis is threefold. 
First, only relatively few alphabets are normally 
used. Second, in this type system they are used 
periodically, imparting the cyclic phenomena in the 
text which in turn provides the means of determining 
the number of alphabets involved. Third, the alpha- 
bets used are known alphabets, i.e. the relative 
sequence of their individual letters are known. This 
with a limited number of alphabets greatly simplifies 
the process of equating cipher and plaintext values. 

b. In preceding paragraphs, when monoalphabetic 
substitution using mixed alphabets was discussed, it 
was pointed out that the use of mixed alphabets 
greatly increased the difficulty of solution. So it also 
is in the case of polyalphabetic substitution. How- 
ever, there are certain characteristics in the type 
mixed alphabets used which permits a fairly easy 
solution. 

c. In paragraph 12-4 the common configurations 
of primary components, and of the derived secondary 
alphabets, used as cipher alphabets were given. In 
_the preceding section, case I was used and the 
analysis based on the characteristics of those sec- 
ondary alphabets produced .in that case. In this 
section, alphabets of case II will be treated and their 
characteristics exploited as the basis for analysis. 

d. Alphabets of case IT are those whose primary 
components are not both normal sequences. That is, 
the plain component may be a standard alphabet 
and the cipher component a mixed sequence; or the 
plain component may be a mixed alphabet and the 
cipher component a normal alphabet. In either case 
the resulting secondary alphabets are mixed alpha- 
bets. An example of the former configuration may be 
seen below in figure 13-11. 


P ABCDEFGHIJKLMNOPQRSTUVWXY2Z 


EREBRBOE REC UU RG LEGGREEchee 
GO OUDGOGGDCELECEECCECEEREG 
ofall fff fa ofc] aes 
e|4|v|u|wlole|ela|e|c|olelo|z|y |x| ml la|s|ulx|y|2| | 


Figure 13-11 


cL 


C2 


C3 


ch 


). Case II secondary alphabets (U). 


13-10. (Cf Direct Symmetry of Position 

a. The secondary alphabets above were produced 
by a juxtaposition of two alphabets. A standard 
sequence as the plain component and 4 of a possible 


26 positional juxtapositions of a keyword mixed 
alphabet based on the keyword LEAVENWORTH. 
The four shown, as well as the other 22 possible 
are in reality only one sequence, each being displaced 
relative to the plain component. Thus in cach a 
direct symmetry exists, ie. in each sequence the 
individual letters follow one another in a fixed 
order at a fixed distance. Since each cipher sequence 
is offset a predetermined distance from the index 
letter of the plain component, symmetry exists 
between the individual letters of each sequence. 

6. The implication of this direct symmetry of 
position can be shown in the example below. Let us 
first assume that in the course of analysis of a poly- 
alphabetic cipher that we have determined that a 
period of four is being used, that the cipher sequence 
used is mixed, and further that the following values 
have been recovered. 


ALPHABET 1 


Ep=Ge Op= Ye Tp=Ve 
ALPHABET 2 

Ep=Ne Op= Ge Tp=Pe 
ALPHABET 3 

Ep=Ic Op= Be Tp=Ic 
ALPHABET 4 

Ep=We Op=Ie Tp=Qec 


The equivalencies shown for the secondary alphabets 
can be set down in a matrix reconstruction diagram 
as shown in figure 13-12. 


P ABCDEFGHIJKLMWNOPQRSTUVWXKYE 


Figure 13-12 (on Letter placement, direct symmetry of position 
U). 


c. As the individual letters of a mixed sequence 
follow one another in a fixed order and as each 
secondary alphabet is the same in respect to the 
sequence of their letters, only positioned at different 
points, it follows then that the letters of one can be 
transferred to another on the basis of constant 
distance and sequence. For example. in) cipher 
sequence 1 above, Ge, Ye, and Ve are noted in sequence 
at 10 and 5 letters distance respectively. This same 
sequence then can be transferred to cipher sequence 2 
where a Ge also appears. By counting 10 spaces to 
the right of Ge, Ye can be inserted below Yp. Con- 
tinuing the count around the alphabet, We can be 


—CONFIDENTIAL— 139 


-GONFIDENTIAL 


located below Dp. For example, note the placement. 


of the values in figure 13-13. 


P ABCDEFGHIJKLMNOPQRSTUVWXY2 


cl 


ce 
a AAIACRAHATOONCHONSCEAIII 
CTT TTT Te 


Figure 18-13 gh . Placement transfer, direct symmetry of posi- 
tion (U). 


d. By continuing the process of the reconstruction 
of the secondary alphabets through the principle of 
direct symmetry of position, the following additional 
placements can be made as shown in figure 13-14. 
Note that two elements must be known. First and 
foremost, one of the components, the cipher or the 
plain, must be a known sequence. It is unimportant 
whether it is mixed or standard, only the the exact 
sequential progression of the letters be known. If 
either is unknown, direct symmetry even if present, 
cannot be detected. Secondarily, given one known 
sequence where the other is unknown, only a few 
equivalencies are required to use the principle of 
direct symmetry. 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


HORACE RRR ACOR RE 


Ut TP el et 
cp MAE E EMRE RCERRRERRSaCE 
om LTE del Te ETT det EE et ET et 


Figure 13-14 (@. Placement transfer (U). 


e. The importance of direct symmetry of position 
in the analysis of a cryptogram should be obvious. 
The new values for each cipher alphabet discovered 
by the process can of course be inserted in the 
ciphertext, thereby leading to the recovery of further 
cipher to plain equivalents. This in turn enables the 
analyst to further develop his matrix reconstruction 
diagram. In short, it has a snowballing effect, each 
step leading to additional recovery until a final 
solution is reached. 


13-11. (DB Preliminary Steps 


a. In the solution of polyalphabetic ciphers using 
mixed alphabets, the same general preliminary 
techniques as those previously given are followed 
prior to the exploitation of the characteristic of 
direct symmetry. Assuming that a cryptogram has 
been identified tentatively as polyalphabetic, it is 
laid out and repeats are underlined as in figure 
13-15. 


13-10 


5 10 15 20 25 
A QWBRI VWYCA ISPJL RBZEY QWYEYU 
B LWMGW ICJCIMUTZETI UIBKN QNUBRI 


G BWNBE@ 


I Q 
D IDMRU VECYG @IGVN CTGYC BPODBL 
E VCGXG BKZ2ZG I 


F Q@L2FCO HMUTY2T CCBAYQ OPEL KA GHUETIE 


KH MYT SY QVFWY RWHP GKNFW NCI KK 
JT IDDRU OPJQQ2RHCN VULDYQ FROGIG 
K BXDBW PXFPUL YAWPFG HPYEL SANCO 


My 
< 
uw 
. + 
c 
lea 
RD 
nH 
Dp 
ine) 
tH 
? 
qy 
é 
my 


P IVJPN WHBR Vv 


ey 
S 
Q 
= 
co 
< 
U 
we 
or. 
| 
b 


Q ATYEW CBYZT 


R XINBA IFKWJQ RDiFY K 


= 
a] 
rh 
la 
og 
> 
4 
¢ 
cay 


S Q@WIJYQ IBWERK 


Figure 13-16 (f). Ciphertezt prepared for analysis (L’). 


b. Once the repeated groups of letters are under- 
lined, they are extracted, set in columnar form, the 
intervals noted, and the factors derived. Note that, 
in figure 13-16 only the factors to 26 are included. 
Beyond that, additional factors would be merely 
repeated cycles of the basic 26 possible alphabets. 


POLYGRAPH IHUTERVAL FACTORS 
QWBRIVWY 45 3, 3,9, 15 
CGXGB 60 25 By hy. 59.65. 0s (Las So, 20 
PJEL 95 5, 19 
22GI 145 oy 
BRIV 330 25°39 S565. 105 22 tS Se 
BRIV 285 355, 155-19 
KAG 75 3, 35 15, 25 
QRD 165 3, 2, 15 
QWB 45 3, 35 9, 15 
QWB 275 5. Ady 25 
WIC 130 2, 5, 10, 13, 26 
XNF ) 3, 25 9, 15 
Yy2r 225 34. Dy ED. 2D 
ZTC 145 5 


Pigure 13-16 (fh. Determination of period (l°) 


The constant factor of five is indicative that all 
repeated appearances are probably causal rather than 
accidental. Further, their number and size reinforces 
this assumption. Therefore it may be accepted that 
the period, i.e. the number of alphabets, is five. 

e. Having determined a probable period length the 
next-step is to make a distribution of the ciphertext, 


—GONFIDENTFIAL— 


one for each period in order to ascertain the type of 
alphabet involved, see figure 13-17. 


Figure 13-17 (U). Uniliteral frequency distribution 
alphabet 1 (U). 


In this case the distribution of alphabet 1 is indicative 
that the period of five is a correct assumption. If 
further confirmation is required, a similar distribution 
for each alphabet could be made and the statistical 
tests previously explained could be used as confirma- 
tion. This is the accepted procedure in most cases. 
However, accepting the assumed period, the distri- 
bution is compared to the normal. In this comparison, 
two facts should immediately become apparent. 
First, the pronounced peaks and troughs are indica- 
tive of monoalphabetic substitution, as it should be, 
assuming the period to be correct. Yet the spatial 
relationship between the peaks and troughs does not 
conform to the normal. That is, it cannot be fitted 
to the normal. Thus, the use of mixed sequences is 
indicated. 


d. If the distribution cannot be fitted to the 


normal, recovery of each value in each alphabet then 
must be determined on an individual basis. Later, as 
values are inserted in the text, additional values may 
be assumed on word patterns, probable words, etc. 
This individual identification may be accomplished 
through a study of frequencies of occurrence, a study 
of a triliteral frequency distribution, or even a study 
of repetitions and assumptions based thereon. 
However, for reasons previously explained, it is best 
to consider all factors. Accordingly, it then becomes 


necessary to develop a triliteral frequency distri- 
bution. 

e. A triliteral frequency distribution made of a 
polygraphic cipher must be somewhat different than 
that made previcusiy in :he case of monoalphabetic 
substitution systems. It must show each letter prefix 
and suffix, and yet account for the fact that there 
are a number of different alphabets involved. In 
order to do this, one distribution must be made for 
each cipher alphabet. In this case, since the period 
length conforms to group size, each successive letter 
of each group is listed in its own distribution, the 
letter preceding and following it is listed below in 
columnar form as a diagraph. Thus a frequency 
distribution for each alphabet and a triliteral distri- 
bution involving three different alphabets is com- 
bined. In the example shown below note that the 
horizontal line A~Z represents those letters from the 
first alphabet. The prefix and suffix listed below each 
letter represents letters of the 5th and 2nd alphabets. 
Thus for reference purpose QAC, the first trigraph of 
alphabet 1, may be annotated 512, as may all 

QAC 
trigraphs from that distribution. In like manner the 
following patterns apply. 


Alphabet 2 123 
SAN 

Alphabet 3 234 
; YAH 
Alphabet 4 345 
ZAO 

Alphabet 5 451 
CAL 


Note that the annotated numbers are merely a cyclic 
permutation of the periodic sequence 1-—2-3-4-5. 
Thus the completed triliteral distribution would 
appear as shown in figures 13-18@ through 13-18@). 


Alphabet 1 
A BC DEFGHIdJK LM NOP QRS TUVWXYZ 
QC GW NT TV AE AS UD UW IT UT QP NX -W LB LA LA IW NN QI UX OR 
PT OP TC AD WC FI QX II UP YW YW DE IW 
GK TT LX HW FW LV OT NW QD RB UE 
OW WB LW ND LR SY QC QD LC 
GL GV WC GI GP 
GX WC GP QL @B 
XD AB AL NW 
GB JF YV QE 
Iv DI NY IP 
NR SW UP 
AK QW 
QB 
Figure 18-18@ (fh. Triliteral frequency distribution, alphabet 1 (U). 
CONFIDENTIAL— 13411 


—GONFIDENTIAE 


Alphabet 2 
A B CC D E F GHI J K L MN OP Q R SS T UV iW XX iY Z@ 
SN RZ IJ IM GG MD MB IW QF WB BD ZH IP MZ IX QB GN MJ 
TG VG QG GG V2 QG BZ BG OD IG CG QF VY BD QA 
JE VG ID SZ QI WW LZ NZ LV QY PP 
MJ CB RG VD KL Os MY IJ LM YN 
SG IG KH MY MI CI EG QB LW 
CY MI RZ XN VI AY VY 
IW Ad VY BN 
Id 
BF 
RN 
VD 
QB 
KF 
GF 
QJ 
Figure 13-18@ B . Triliteral frequency distribution, alphabet 2 (U). 
Alphabet 3 
A B C D E F G EHIé J K LM N O P Q R § T UV W X Y Z@ 
YH WR PB BY WE CQ RC IE CC IC WG WB SJ WV PM VC WC BE 
Ik PK LC EX DC WK DR WF Of WE TE 
WR DR VW IV YI XF BR WI EY 
cY WY XP TY CK XxF TZ KZ 
WI XB WZ CX . PR Ac IZ TA 
NR FZ WJ DI PE XC ; TE EZ 
EC CX PJ IB BZ RN 
LQ TR PH DY 
BR CR 
DD VR 
BZ PE 
AD WY 
FQ 
VQ 
Figure 13-18@ (@). Triliteral frequency distribution, alphabet 3 (UV). 
Alphabet 4 
A B C DE F GH I Jd K LM N oO P R S$ T UV W X Y Z@ 
ZO NQ YA GG ZY WL MW AQ YG PL BN WR ZQ FU GH BI GN FY GN ZG ZG 
DL JI GN YU NW XL GG JY dA GQ BI GG GO YT 
DN XU ZI NG BI JF DA JQ MU GG BQ 2G 
A FO FQ WQ JX GP GS DQ DT 
HN IW FQ GU DU EU YQ 
ND JL JD ZF Gi 
HA JL JR JQ YT 
LJ YW JN FL 
DQ BI 
NL WX 


Figure 18-18@ A. . Triliteral frequency distribution, alphabet 4 (U). 


13412 —GCONFIDENTIAL_— 


—-CGONFIDENTIAL 


Alphabet 5 


A.B CD ek Gs - He i Be 


CI CS JK IB QI RV CM JR 

KG RM YK YQ CM BV 

KG xB. OEM FG 

CM ZI. RV ES 

BI IV IT CL 
XB RV ET 
DB aL 
FM ZG 
ae 


MN OP. 8. Rk 6. PF UV Wk. te 
KQ@ YB QA BQ MQ RM ZC EL GI KI EQ 
XI AB EQ RS CQ ZC RV EI R- JQ 
VC Ct YO ZE CN FM WR 
cv QV RO EC 
BP QZ PY 
2Q YR YK 
RW ZA QV 
DI HV 

CL 
NX 
JR 
JQ 
aL 


Figure 13-186) o. Triliteral frequency distribution, alphabet 5 (U). 


f. In addition to the triliteral frequency distribu- 
tion a condensed table of repetitions is prepared in 
which all polygraphs are listed and the alphabet of 
each letter is indicated. A format of this is shown in 
figure 13-19. 


13-12. (CY Identification of Cipher Values 


a. With the completion of the preliminary step. 
the analysis of the cryptogram may now begin. 
Using the same analytic techniques as were used in 
the case of mixed monoalphabetie ciphers, one now 
attempts to establish the identification of cipher 


7 < : 2 2 : 25 ; 2 = 2 55 values, doing this for each alphabet. The first step 
QWB re PS-EE <2. is to separate the vowels from the consonants— 
QW -5 Li P -2  . through frequency of occurrence alone, or by the 
WP = CG 3 consonant line method in doubtful cases. On the 
a S a 
3 hs 3. WB 3 basis of the former it appears that We and Qe are 
BPI V-3 WE -3 the equivalents of Ep. In the other alphabets this 
Z22G I-2 WY =3 distinction is not so clear-cut. Using the same 
Y2T +2 xi -3 1 3 4 
; i = 512 yardstick of frequency as a measure Ic, Ge, and Ce 
GX a3 QR D-2 appear as likely candidates for Ep. 
JR -3 WI C-2 b. In paragraph 13-lle it was stated that the 
WF -3 GB -4 triliteral distribution of alphabet 1 represents the 
YZ ~3 Iv -3 letters of alphabets 512 as prefix, base, and suffix 
bs 1 Ca 8 letters respectively. As the cipher value of Ep has 
K A G-2 been assumed with some certainty for alphabets 2 
“7 C-2 2 5 
RI -3 and 5 (We and Qc), we may use this to determine 
; = the vowels and consonants of alphabet 1. The basis 
for the identification being the familiar diagraph 
Figure 13-19 (G). Condensed table of repetitions (U). permutations of E, that is: 
E as beginning letter ED EN ER ES 1 


E as ending letter 


NE RE SE TE VE 1 


13-13 


—GONFIDENTIAL— 


In terms of the 512 pattern, possible cipher to plain 
equivalencies may be set down as illustrated in 
figure 13-20. 


D1 51 DL 51 
EDp ENp ERp_ ESp 
Q@-e Q-e Q-¢ Q-«e@ 


12 12 12 12 12 
NEp REp SCp Ep Ep 
-We -We -We ~We -We 


Figure 13-20 (%). Identification of cipher to plain 


equivalencies (U). 


Thus it can be seen that some of the high frequency 
letters of alphabet 1; J, M, Q, V, B, G, L, R, S, and 
C respectively, probably represent the plaintext 
consonants D, N, R, 8, T, and V. Moreover if the 
consonants can be identified, then the remaining 
high-frequency cipher letters of alphabet 1 most 
likely will be limited to vowels. 
2 5 


ce. The prefixes of We and the suffix of Qe (both 
assumed Ep) are shown in the following tabulation 
figure 13-21, drawn from the triliteral distribution 
of alphabet 1. 


Figure 18-21 (G). Identification of vowels and consonants (U). 


Using the data established, it is now possible to study 
the high-frequency letters, I, M, Q, V, B, G, L, R, S, 
and C of alphabet 1 in turn, to determine their 
identity as either a vowel or consonant, and perhaps 
ascertain their exact plaintext value. 

1 

(1) Je previously established as a possible cipher 

value for Ep may be set aside immediately. 

2 


(2) Me is noted as not appearing either as a 
suffix or prefix in the tables above which indicates 
that it may be a vowel. Moreover its frequency tends 
credence to this. If it is a vowel, it may well be Op, 
as Ep has been excluded, though its identification as 
either an Ip or Ap cannot yet be discounted. 


13-14 


1 2 
(3) Qe is observed five times as a prefix of We 
5 
and three times as a suffix of Qc. The frequency of its 
combination with assumed Ep indicates both that it 
is probably a consonant and that it is the equivalent 
of Rp. 
1 
(4) The letter Ve occurs three times as a prefix 
and twice as a suffix indicating that it, too, is prob- 
ably a consonant. On the basis of its frequency it then 
may be assigned the plaintext value of T. 
1 2 
(5) The letter Be occurs only as a prefix of We. 


then only twice. As its frequency is neither low nor 


high, it may be a consonant. 
1 

(6) Gc appears but once, as a prefix; its identity 
is questionable, though it may be either Ap or [p. 

is 

(7) Le appears one time as both a prefix and a 
suffix, therefore it is probably a consonant, yet its 
exact identity cannot be ascertained. 

“ 

(8) Re, because it appears once as a prefix and 
twice as a suffix of the assumed Ep, is most certainly 
a consonant. 

1 1 

(9) Neither Sc nor Cc appears as a suffix or a 
prefix; therefore, both may be vowels or consonants, 
though a study of their combinations later, in other 

1 1 
sequences, shows that Ce may be a vowel leaving Sc 
unclassified. 

d. The same process is applied to each clistribution 
in turn classifying the cipher letters either as vowels 
or consonants, and identifying specific plain to cipher 
values where possible. Also, as the process is con- 
tinued, it then becomes possible to expand the 
classification and identification by playing one 
assumed value of one alphabet against an unidentified 
vowel or consonant in another, thus leading to 
additional identifications. The completed process 
could result in the following classification of vowels 
and consonants. Also previous identifications could 
be placed in a reconstruction matrix as shown in 
figure 13-22. 


Alphabet Vowels Consonants 
1 I, M,C Q, V, B, L, R, G? 
2 W,P,I B,C, D, T 
3 G, Z J,N, D, Y, F 
4 C; E?, R?, B? Y, Z, J, Q 
5 Q, U G, N, A, I, W, L, T 
Pp 
cl 
c2 
c3 
ch 
cs 


Figure 18-22 eS. Reconstruction matriz (U). 


13-13. (& Application of the Principle of Direct 
Symmetry of Position 

a. At first glance the values recovered to this point 
seem somewhat sketchy. However, on a closer 
examination the appearance of Qc in both alphabets 
1 and 5 is noted as well as the Cc in alphabets 1 and 4. 
If the cipher system involves the use of one mixed 
component juxtaposed a number of times against a 
known standard sequence, the resultant secondary 
alphabets (cipher alphabets) can be recovered by 
applying the principle of direct symmetry of position 
presented above. If this is the case then the values of 
alphabet 1 can be transferred to alphabet 5 using the 


5 


Qc as point of reference. It would appear as shown in 
figure 13-23. 


P A BCDEFGHI JKLMN OPQRSTUV WXYZ 


fed | ie feed | TUT bl tl 
et lite TT Eel led 


Figure 13-23 (C). Recovered value transfer (U). 


b. This process immediately reveals three addi- 
5 5 

tional values; Mc=Bp, Ve=Gp, and Ic=Rp. Note 

that Bp and Gp are normally low-frequency letters. 

If the values derived by this process are correct, 

Me and Vc of alphabet 5 should appear infrequently. 


468-095 O-72 - 13 


A check of alphabet 5’s distribution reveals that 
neither appear, which tends to support the assump- 
5 
tion. Note that Ce in alphabet 5 appears under Np 
and Vp. Both are consonants, but are significantly 
5 
different in that if Ce=Np, H can be expected to 
6 
appear quite frequently. If on the other hand Cc is 
Vp it will appear infrequently. Examining the dis- 
tribution for alphabet 5, it does not appear at all, 
therefore it must be equivalent of Vp rather than 
5 
Np. The definite placement of Ce now permits the 
placement of values in alphabet 4. The total values 


now consolidated in the reconstruction matrix appear 
in figure 13-24. - 


P ABCDEFGHIJKLMNOPQRSTUVWXKYZ 


oT el TTT al Tel PT 
ett tt TTT 

es [IT | |e | 

ch 

cs 


Figure 13-24 i. Additional value placement (U). 


c. At this point it 1s possible to transfer the values 
found to the cryptogram. It is possible to continue 
along the same lines, i.e. determining the value of 
individual cipher letters through association with 
those already found, confirmed by their use in other 
alphabets. However, with the number of values 
already recovered it may be more profitable to 
approach the problem directly through the analysis 
of word patterns in the ciphertext. 


13-14. (1 Reconstruction of the Matrix 


a. Using the partially recovered matrix, the fol- 
lowing plaintext values can be inserted in the cipher 
work sheet (fig. 13-25). 


13-15 


—GONFIDENTIAL— 


5 10 15 20 25 
A- QWBRI VWYCA JISPJL RBZEY QWYEU 
RE R TEE E RE 
B LWMGW ICJCI MTZEI MIBKN QWBAI 
E E ER O R O RE R 
C VWYIG BWNBQ QCGQH IWJKA___GEGXN 
TE A E E REN EE E 
D IDMRU VEZYG QIGVN CTGYO BPDBL 
E T R EP IE 
E  VCGXG BKZZG IVXCU WNTZAO BWFEQ 
TE E E E E 
F QLFCO HTY2T CCBYQ OPD GDGIG 
R E o If I &E EA 
G VPWMR QIIEW ICGXG BLGQQ VBCRS 
tT K R EE EVE TE 
H MYdJY QVFWY RWNFL GXNFW  MCJKX 
6) R E 0 
J  IDDRU OPJQQ  ZRHCN VWOYQ  RDGDG 
E NE E TE E E 
K  BXDBN  PXFPU YXNFG WPJEL SANCD 
0 E 
L SE2ZZG  IBEYU KDHCA MBJJY KILCY 
E E fe) E 
M MFDZT CTJRD MIYZQ ACJRR SBGZN 
) I Oo 6; E 
N  QYAHQ VEDCQ LXNCL LVVCS QWBII 
D -E EE E E RE AR 
P IVJRN WNBRI  VPJEL TAGDN IRGQP 
E R T E E EN 
Q ATYEW CBYZT EVGQU VPYHL LRZNQ 
I ENT E 
R  XINBA IKWJQ  RDZFY KWFZL GWFJIQ 
E E E EE 
S QWIYQ IBWRX 
RE E 5 


Figure 138-25 (@). Partially recovered plaintert (U). 


5. Possible words are somewhat sketchy, but no 
impossible combinations are noted. Therefore the 
plaintext values would be carefully scanned in an 
attempt to locate possible words. In line A, a word 
fragment is at once noted. 

5 10 15 
A QWBRI VWYCA ISPJL 
RE--R TE-E E 


(1) The same pattern occurs on line B as: 


12345 12345 12345 
B QWBRI VWYIG BWNBQ 
RE--R TE-A E E 


Considering possible words which may be used as 
the beginning of a message, the word REPORT is 


13-16 


quickly selected. Note that the E which follows it 
may be expanded to REPORTED. Thus the follow- 
ing cipher to plain value may be assumed. 


3 
Bene 
4 ; 
Reo 
3 
me 


(2) A similar pattern is noted on line L 


§ 12345 1 
S QWBII I 
RE ARE 
“ae 
Having established the values of Bc as Pp it leads 
immediately to the assumption that this plaintext 
5 
fragment represents PREPARE and that Se=Pp. 
(3) Another pattern of interest occurs on lines 
E and F. Note the word fragment: 


12345 12345 
CDGIG VPWMR 
EA T K 


This may represent the word ATTACK, and if so 
the following values could be assumed: 


5 
The assumption that Ge=Tp is confirmed at the 
second appearance of REPORTED. Note that this 
value completes the phrase REPORTED AT. 

(4) Reexamining the text in light of the pre- 
vious assumptions, additional values may be gleaned. 
For example, beginning at AQ another possible word 
is noted. 


Al 


SQ ere 
ma oO 
Qk 
BY ot ocr 


123 
ISP 
E 


With a little imagination the word ENEMY can be 
seen in the similarity of the placement of the E. 


_CONFIDENTIAL— 


—CONFIDENTIAL— 


Further, it seems to make sense in that the phrase 
REPORTED ENEMY would appear at the opening 
of the message. If the assumption is correct then: 


5 2 3 
Acs NP: Se MP and Pe YP 

c. The process outlined can be continued, as long 
as probable words can be seen in the text. However 
there is danger in this unless the assumptions are 
checked periodically for validity against other factors. 
In this case, the assumed values shown below can be 
compared to their respective frequency distributions. 
If no significant differences are noted, then they may 
be placed in the reconstruction matrix: 


New assumed values 

Alphabet 1 

Alphabet 2 Pe=Ap, Se=Mp 

Alphabet 3 Be=Pp, Ye=Dp, We=Cp, Pe=Yp 
Alphabet 4 Re=Op 

Alphabet 5 Se=Pp, Ge=Tp, Ac=Np 


13-15. 4) The Reconstruction Matix 


a. The values previously established when inserted 
in the reconstruction matrix would result in the 
matrix shown in figure 13-26. 


P ABCDEFGHISJKLMNOPQRSTUVWXY2 


ce ii 
3 nna 


cs i Onin 
05 {dul | fel Tel PTET T tal Est fel del fel | 


Figure 13-26 (fh . Insertion of recovered values (U). 


In so doing an inconsistency becomes apparent. Note 

P CDF P RST 
the sequences C WY G in alphabet 3 and C [-G 
in alphabet 5. If, as has been assumed, the same 
sequences are being dealt with, this is an impossible 
situation. One or the other must be wrong. Therefore 
the value of each must be reexamined. In alphabet 3 

C D 


the values W and Y were derived by analysis while 

the position of Ge below Ep was purely on the basis 

of inspection of the frequency distribution. The 
5 

placement of Ge below the Tp was on the basis of 

assuming the word ATTACK. Therefore it is now 


~CONFIDENTIAL— 


3 
determined that the initial assumption of Ge as 
Ep is incorrect. Yet, as seen in the triliteral frequency 

3 

distribution, Gc behaves like a vowel, therefore it 
should be replaced beneath a vowel other than E 
But which one? Perhaps an answer can be found by 
ignoring the Ge in alphabet 3 for the moment and 
applying the principles of direct symmetry of 
position to transfer vowels. Thus the matrix would 
now appear as shown in figure 13-27. 


P ABCDEFGHIJKLMNOPQRSUTUVWXY2Z 


Figure 18-27 (C). Insertion of recovered values, step 2 (LU). 


b. The relative position of letters in each sequence 
is such that the use of a keyword mixed alphabet as 
the secondary component can be safely assumed. 
In particular, note the sequence M — - QRV in alpha- 
bets 1, 2, 4, and 5, WY in alphabet 3. Note also 
the A—S-I-G-C sequence, again in alphabets 1, 2, 
4, and 5. These sequences are reminiscent of portions 
of a keyword; A-S-J-G-C being the keyword, 
possibly the @ marking its end; the QARV being a 
mid portion, and WY of alphabet 3 marking its 
end. Previously in alphabet 3, G@ was incorrectly 
placed immediately following the Y. Perhaps, in- 
stead, a Z should be placed there. In the case of 
the sequence M — - QRV, O and P should be placed 
between the M and Q; thus, N could be placed 
between the 7 and G of the sequence .1-SOJ-G-C. 
If this was done G would then fall beneath a vowel 
in alphabet 3 as required. This placement would 
then allow the reconstruction matrix to be expanded 
(fig. 13-28). 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


cl [A SURUUGUGRERRRZE 

: ‘AbvittLCETEL 

c3 

ch 

“ SQRCRGEGSG 


Figure 13-28 os. Expansion of matriz (U). 


13-17 


-CONFIDENFIAL— 


13-16, (5 Completion of the Solution 


a. Having reached this point in the analysis, the 
next step is to again transfer the newly assumed 
plaintext values to the cryptogram being studied. 
The object is twofold. First, by so doing the validity 
of the assumptions may be proved or disproved, 
according to the structure of the resultant plaintext 
produced. Second, if the assumptions are proven 
valid, their insertion into the cryptogram will 
enable the analyst to assume new plain-to-cipher 
values. Accordingly, this will produce the following 
partially recovered cryptogram (fig. 13-29). 


5 10 15 20 25 
A QWBRI___VWYCA ISPJL BZEY  @QWYEU 
REPOR  TEDEN EMY SRE I RED 
B  LWHGW ICICI MIZEI MIBKN QWBRI 
EWCH ESTER OER OOPS _ REPOR 
C VWYIG BWNBQ QCGQH IWJKA  GEGXN 
TEDAT HENDE RSON EE NY GOS 
D  IDMRU VEZYG @IGVN CTGYO BPDBL 
EWO TERT ROOPS ORC HAD 
E VCGXG _BK22G___IVXCU NTZAO  BWFEQ 
_ ™S0T dH EST EDE FEWC HE E 
F  QLFCO MTYZT__CCBYQ  OPDKA___GDGIG 
R EC ODS  ISPRE PA WN GOT 
G  VPWMR QIIEW  ICGXG BLGQQ  VBGRS 
TACKF ROMH ESO T HONE TROOP 
H  MYJSY QVFWY RWNFL GXNFW  MGJKX 
OF I RDQI SEN GNH os 
J IDDRU OPJQQ  ZRHCN VWDYQ RDGDG 
EO PAN WCES TERE SOT 
K  BXDBN PXFPU YXNFG MPJEL  SANCD 
H DS QM VNT OA CKNE 
L SEZZG__IBEYU KDHCA MBdJY  XKILCJ 
CEST ERR EN OR OE 
M  MFD2T CTJRD MIY2ZQ ACJRR SBGZN 
o S I 0 OODSE AS OF CROSS 
N QYAHQ  VEDCQ LXNCL LVVCS QWBII 
RFIE T EE NE DBEP  REPAR 
P IVJRN WNBRI_VPJEL TAGDN IRGQP 
ED OS UPPOR TA KO S  ECOND 
Q  ATYEW CBY2ZT EVGQU VPYHL  LR2NQ 
ADH  IRDS DON = TAD CEBE 
R XINBA IKWJQ__RDZFY  KWEZL GWFJQ 
oNDN ECE  S ER ES CE E 
S QWIYQ  IBWRX 


RE RE ERCO 
Figure 13-29 p. Plaintext partially recovered (U). 


13-18 


b. With the wealth of plaintext values now added 
to the cryptogram, the final solution is quite simple. 
With but little effort, the plaintext can be inferred. 
For example, line A and the first group of line B 
reads: 


REPORTED ENEMY HAS RETIRED TO. 
NEWCHESTER 


Using the values established by this assumption, 
the basic cipher sequence, again through the process 
of direct symmetry of position, can be expanded 
to: 


C1. AUS INGBC J LMNOPQRVWYZE 


with only the letters D, F, H, K, T, and X unplaced, 
recovery of the keyword follows immediately. 
Considering the positional limitations of the se- 
quences, the keyword mixed sequence is derived as: 


EXHAUSTINGBCDFJKLMOPQRYV W YZ 


and the repeating key is APRIL under Ap. 


c. A reconstruction of the cipher matrix using 
the above key and sequences reveals the message as: 


REPORTED ENEMY HAS RETIRED TO 
NEWCHESTER(.) ONE TROOP IS_ RE.- 
PORTED AT HENDERSON. MEETING 
HOUSE(.) TWO OTHER TROOPS IN OR- 
CHARD AT SOUTHWEST EDGE OF NEW- 
CHESTER(.) SECOND SQ IS PREPARING 
TO ATTACK FROM THE SOUTH(.) ONE 
TROOP OF THIRD SQ IS ENGAGING 
HOSTILE TROOP AT NEWCHESTER(.) 
REST OF THIRD SQ IS MOVING TO 
ATTACK NEWCHESTER FROM THE 
NORTH(.) MOVE YOUR SQ INTO WOODS 
EAST OF CROSSR(OADS) FIVE THREE 
NINE AND BE PREPARED TO SUPPORT 
ATTACK OF SECOND AND THIRD 5Q(.) 
DO NOT ADVANCE BEYOND NEW- 
CHESTER(.) MESSAGES HERE(.) TREER, 
COL(.) 


-GONFIDENTIAL—— 


Section Ill. (Cf SPECIAL CASES AND THEIR SOLUTION 


13-17. (CY Solution of Message Using the Same 
Alphabets—Different Key—Completing 
the Plain Component 

a. It sometimes happens that correspondents will 
use the same primary components to encipher a series 
of messages, only using a different key for each 
message. In this case, if one message is recovered and 
the primary components are reconstructed, the situ- 
ation is then one of a message enciphered using a 
known sequence. Thus the possibility arises that all 
subsequent messages can be solved by completing 
the plain component. 

b. In previous paragraphs it was shown that, in the 
case of monoalphabetic ciphers, completion of the 
plain component was based on inscribing a normal 
alphabetic sequence below the plain component 
equivalents, the plaintext then appearing on one 
generatrix. Also, as was shown in the case of poly- 
alphabetic ciphers using standard alphabets, the 
plaintext equivalents of each alphabet involved 
reappeared on the same generatrix; thus it was only 
necessary to combine the proper generatrices to 
reproduce the plaintext. In the situation under dis- 
cussion both processes are combined. The techniques 
involved are explained in the following paragraphs. 

c. Presupposing that the message in figure 13-30 


was enciphered using the same primary components . 


5 10 15 20 25 

A SFDZR YREKX MIWLL AQRLU RQFFRT 

B IJQKF XWUBS MDJZK uTCQC UDPIV 

Cc TYRNH TRORV BQLTI QBNPR RTUVHD 

D PT. IVE RMGQN LRATQ PLUKR KGRZF 

E JCMGP IHSMR GQRFX BCABA OEMTE 
F PCXS HH RGQSZ VB 

Figure 138-80 (C). Ciphertext for analysis (U). 

PP ABCDEFGHIJSKE 

C EXHAUS TINGB 

12 3 4 5 

C S FDZR 

P-P FNMZY 


SIN OQN 
Man oe 


as were used in the preceding example, the first step 
is to determine the period or number of alphabets 
involved. 

(1) The size of the sample and the repetition 
MRGQ occurring at an interval of 21 suggests poly- 
alphabetic encipherment with a period of either 3 or 
7. The repeated trigraph DPT at an interval of 28 
tends to confirm the period as being 7. Thus the 
message is then transcribed into seven columns— 
each column corresponding to one period, indicating 
the use of one alphabet. 


Qn bata SPONSES QR ENA 


DNHQARERHEVSe RS FSFORGKNADS 


B 
M 
M 
VB 


(2) With the message rearranged to reflect the 
use of its alphabets, the following step consists of 
converting each column to a plain component 
equivalent. This is done by juxtaposing the recon- 
structed cipher component against the normal 
plain component at any arbitrary point. then listing 
the pseudo-plain equivalents in columnar form 
reading from the cipher component, as follows: 


MARWAN SADHDITIOAS RONDA 
Ne OM SEAN TQH ORS OD Rye 
Gy aumyyCO DYHQAQUM ROMY 
AABAAROADVVORVEBWYVAISyWo 
DUVWOVBVONQROAQHNHODWHADN 


N Q 
F L 


NN 


S T 
O P 


py 


0 P UVWwWSs 
JK QRVW 


13-19 


For this it is not necessary to convert all rows—just 


a sufficient number to form a basis for the subsequent 
step. In this case 10 rows will do: 


(3) Selecting the first five lines of plain com- 
ponent equivalents produced by the preceding step, 
a generatrix diagram is produced for each by in- 


123 4 5 6 7 scribing, in columnar form, the normal alphabetic 
P-P FNMZVYV sequence below each letter. Each generatrix so pro- 
VPBRHX®Q duced is then rough scored using the methods shown 
QadDUVQEYV in paragraph 13-56. This process is illustrated in 
UNVGHOU figure 13-31. 
PNBEXKF 
RMOZPRE 
LULEMTG 
WGYVvVIIC@é 
VS VWEKEKU Q 
GHUKITV 
Gen. Alphabet 1 Alphabet 2 Alphabet 3 Alphabet 4 Alphabet 5 
Cipher SRLQKMCVRT FKAFFDQTOL DXQRXICYRQ 2MRTUZURVB RILIWKDNBN 
1 1 FVQUPRLWVG 4 WNPDNNMUGSH 1 MBUVBOLYVU SRVGEEEYWH YHQHXPHL KT 
2 GWRYQSHXWH T OQEOONVHTI 1 WNCVWCPMZWV 3 ASWHFAFWXL WERT YONI LE 
3 HASWRENYXE 3 PREPPOWIUS OBWADQNALW BLALCBGALE tad SA SEOKEHK 
4 FYTASUOSIS QECQQPXIVH PEXYSROBYLX CUFSHGHYZH ¥RZRKASP LAL 
5 JZUYTVPAZK RIHRRQYRWE @FYZESPCZY DVZKLELEAO BLU LBIQHOH 
6 KAYSUWQBAL SYFSERZEXM REZACLQDAS BWALIEPABP 3 AMVMCURNPN 
7 2 LBWAVXRCBM 6 TVJTTSAMYN 5 SHABHUREBA EXBHKFRBGQ 5 BNWNDVSOQC 
8 2 MCXBWYSDCN UWHUYTBNZO 4 TIBCIVSFCB 2 GYCNLGLCDR 5 COXOEWTPRP 
9 HD¥CXZIEDO 2 VXLVVUCOAP EICDIWFEDE 3 HZDOMHMDES DP¥PFHUQSE 
10 4 OEZDYAUFEP 0 WYMWWVDPBQ VEBDEKAUHSD 8 IAEPNINEFT BQZQCLVRER 
a8 PRAEZB YGF WENKXWEQCR 3 WLEFLYVIFE PBEQCPOFGY 5 FRARHZWSUS 
12 2 QGBFACWHGR 4 YAOYYXFRDS HME GUZWEIGE HGGRPKPGHY 6 GSBSIAXTVT 
13. 3 RHCGBDXIHS BBPZZYGSEL ¥NGHNAXKHG SRHSQLQHZW 2 HATCTIBYUWU 
14 5 SIDHCEYJIT AGQGAASHFFU & ZOHIOBYLIH HBLFRURISK FUBUKEZUKY 
15 FIBLDFEKIY 3 BDRBBAIUGV APLIPCSUIFT NESUSHEPK¥Y 2 JVEVLDAWYW 
16 BHEFBGALKY 2 CESCCBJVHW BEFKQDANKS OGHYPOFRES KWEWHEBASH 
17 O VLGKFHBMLW DETODCKWEX GRKEREBGEX 1 PHLWUPULMA EAGHAEC LAL 
18 2 WMHLGICNMX BGUEEDEXI¥ 2 DSLMSFCPML QZUXVQVMAB M¥H¥OGDEBZ 
19 ANTM SF DONY BPHYPPEMEHSZ 5 ETMNTGDQNM 5 RJNYWRWNOC HZELSPHEAGA 
20 ¥O¢NEHEPOZ 3 GIWGGFNZLA 6 FUNOUHERON SKOZKSKOPD bad AgTEBES 
21 SPROSLEQPA H¢XHHGOAMB 4 GVOPVIFSPO 4 TLPAYTFPQE PBKBRIGCEG 
22 AQEPHHGR@B 4 IKYIIHPBNC HWPQWEGLOP GMQBZUZQRE QCLESKHSED 
23 4 BRMQLNHSRC FhodedFQCOD ZHQRKKHUR@ 6 VNRCAVARSG 5 RDMDTLIEGE 
24 7 CSNRMOITSD KMAKKSREPE 5 JYRSYLIVSR 4 WOSDBWBSTH 4 SENEUMJFHF 
25 6 DTOSNPJUTE ENBLLXSEGF KES PoHIWES APTEGKCSEL 4 = TFOFVIIKGIG 
26 BUPTOQKVUF 3 MOCMMLTFRG LAPUANKAUP ¥QUFD¥YDUVE 1 UGPGWOLHI 
Figure 13-31 ). Rough scoring of generatrices (U). 
13-20 CONFIDENTIAL — 


-GONFIDENTIAL — 


(4) Those generatrices with the highest score 
are then set down in columnar form to determine if 
they will yield plaintext. 


Alphabet 12 3 4 5 
Generatrix 24 2 20 10 12 
COFIG- 
SQUAS 
NENEB 
ROOPS 
MOUNI 
ONHIA 
IVENX 
THRET 
STOFV 
DINTT 


(5) The presence of plaintext in the matrix is 
obvious. However, it is also noted that generatrix 
12 of alphabet 5, although the highest word, is not 
correct. Therefore another is selected in its place. 
Also, since a period of seven was initially assumed, 
the diagram is expanded to include seven columns, 
the previous step being completed to produce the 


necessary generatrices. Thus the text would appear 
as: 


Alphabet 12 3 4 5 6 7 
COFTRST 
5 QUAD RO 
NEN EM YT 
ROOPDI 8 
MOUNTED 
ONHILLF 
IVENINE 
THREEWE 
STOFGOO 
DINTENT 


(6) Comparing the first period of plaintext 
with the first period of ciphertext, and setting the 
plain and primary components so as to produce the 
equivalency shown in each alphabet of the period, 
the key may be recovered. For example, in 

12 3 4 5 6 7 
P COF IRs T 
Cc SF DZRYR 
it is observed that Cp=Sce. This equation can be 
duplicated by juxtaposing the two primary se- 
quences so: 


ABCDEFGHIJKLMNOPQRSTUVWXYZ 
EXHAUSTINGBCDEFIJKLMOPQRVWYZEXHAUSTINGBCDFIKLMOPQRVWYZ 


Thus Ap= Ae. 
Continuing the process of juxtaposing it will be 
found that 


when then 
C p= Se Ap= Ae 
Op= Fe Ap= Ze 
F p= De Ap= le 
I p= Ze Ap= Me 
Rp= Re Ap= Ue 
Sp= Ye Ap= Te 
T p= Re Ap= He 


The repeating key then is AZIMUTH. Using this, 
the enciphering matrix can then be reconstructed 
and the entire message deciphered. 


13-18. The Principles of Matching—Solution 
of Messages Involving an Unknown 
Component 

a. In the preceding example the proposition was 
the solution of a message where both the primary 
plain and cipher components were known. The 


CONFIDENTIAL — 


key—which controlled the successive juxtaposition— 
producing the secondary cipher sequences. was the 
unknown element. This case is one where only the 
primary cipher sequence and key length is known, 
the key is unknown, and the primary plain ecom- 
ponent is unknown. The normal condition, i.c. 
where the plain component is known, permits the 
use of the principle of direct symmetry of positions. 
In this case where only the cipher sequence is the 
known element, the use of direct symmetry of 
position or completing the plain components is 
prohibited. Instead, the principle of matching may 
be used. 

6. This principle is founded on the fact that a form 
of symmetry, in this case spatial, exists between the 
successive peaks and troughs of secondary cipher 
sequences which are produced by the juxtaposition 
of the two primary components. This spatial sym- 
metry can be seen in the following distributions, 
figure 138-32, drawn from a eryptogram produced by 
the method under discussion which involved five 
secondary alphabets. 


13-21 


CONFIDENTIAL 


Alphabet 1 


~=. 22z- 


ABCDEFGHIJSKLUNOP® 


Figure 13-32 ( 


Note that in each of the distributions the spatial 
relationships between the peaks and troughs remain 
constant, but that between distributions, their 
positions relative to any given letter differ. In this 
case, the highest peaks occur in successive alphabets 
above the Ne, Ke, Ac, Bc, and Ec in that order. The 
spatial symmetry is a result of juxtaposing one fixed 
sequence against another fixed sequence. The differ- 
ence between the relative location of the peaks and 
troughs in each distribution is the result of using 
successively different points of juxtaposition. 

c. It was remarked earlier that a periodic poly- 
alphabetic cipher was really nothing more than a 
series of monoalphabetic substitution ciphers used in 
a periodic or cyclic manner. Thus each period, as 


13-22 


z_ 
ZX = _B_=2zzZ 
RSTUVWXYZ 


. Uniliteral frequency distribution, secondary cipher sequences (U). 


reflected in the distributions, will show to a greater 
or lesser degree the normal frequencies of mono- 
alphabetic usage. Spatially, in the case where both 
components are standard, it will be the same as the 
normal, only offset to the same degree as were the 
primary components. Where mixed components are 
used in either or both components, this spatial 
relationship, relative to the normal, is lost. However. 
the frequency of usage of individual letters, as 
reflected in peaks and troughs, remains. The fact that 
this can be observed at all indicates that the cipher 
sequence is a known sequence. Note that in the above, 
the cipher sequence is known, and in this case is a 
standard alphabet. However, when the cipher alpha- 
bet is a mixed alphabet, the same principles will 


CONFIDENTIAL —— 


-CONFIDENFIAL— 


apply if its sequence is known. But in that case, the 
distribution must be made using this sequence of 
letters. In either case, if the wrong sequence is used 
the symmetry between each distribution will be lost. 

d. With the knowledge that each distribution is a 
monoalphabetic distribution reflecting the under- 
lying plaintext, several possibilities are immediately 
opened. First, by matching the peaks and troughs of 
each and bringing them into agreement, relative 
equal values can be determined. That is, Ne, Ke, 
cle, Bc, and Ec, the highest frequency letter of cach 
distribution, can be equated as representing the 
same plaintext value. If this is so, then, because of 
the similar spatial relationship between each distri- 
bution, all letters can be equated. Second, as the 
peaks and troughs represent the underlying plain- 
text frequencies it becomes possible to identify an 
equated series of letters to one specific plaintext 
value. Barring the fact that specific identification is 
possible, the assignment of an arbitrary plaintext 
value to each set of equated cipher values permits 
the reduction of the plaintext to monoalphabetic 
terms. The first step then is matching the distribu- 
tions. This involves the cyclic shifting of the alpha- 
bets as seen in figure 13-33. 


Alphabet 1 
Treo er Ort CE wNorOReTOT we 2 
Alphabet 2 
= == = ne z= =z 
= ~2 32322222222 _2=222= 22 _ 
XYZABCDEFGHITKLMNOPQRSTUVYW 
Alphabet 3 
= = = = =z 
a _- 222-2 B22 = .= = S=_ 
GR Bae iy a ink 
Alphabet 4 
=m = = z 
aaj —-=zz 22 _ 
OPQRSTUVWXYZABCDEFPGHIST KLINE 
Alphabet 5 
zs 5 = . 
— 3 == 
= -2_=2 22—- Zi=. £#zZ= 
eek a ea CR Ue ae ee hee 
Figure 13-33 . Matching by cyclic shifting (U). 


—GONFIDENTIAL— 


(1) Note that in the above, the sequence Ne, 
Ke, Ge, Be, Ec, was used rather than the sequence 
Ne, Ke, \c, Be, Ec, previously used as a frame of 
reference. This is because the alinement of -le to the 
other values resulted in the mismatch of the remain- 
ing high-frequency letters. This is a reflection of the 
necessity to gain the best alinement of all peaks and 
troughs. Once the alphabets have been alined, a set 
of arbitrary plaintext values can be generated. This 
can be done by substituting the values of alphabets 
2-3-4 and 5 in the ciphertext, for the value directly 
above it in alphabet 1. Thus whenever Xe, Tc, Oc, 
and Re occurs in the cyelic positions 2, 3, 4, and 5 
respectively, an cic is substituted. This process, the 
reduction to monoalphabetic terms, converts the 
ciphertext to the form shown in figure 13-34. 


) 10 15 20 25 


A QHVHT LUTXI JYNFP UNG 


uy 
ia 


T EYUFE 


ny 
tos 
~ 


F 
B EUTGN VUGYX YDHRYY ONLUS ST 
J 


C YKTYN GTHYK UTHJA HXMUND KTFYD 
D NHSHC KTPXN KCIGN VOPNT NGHAIK 
E XXKSU LDOKHT PRHEKK DHURKT LOKTEH 
F BYURE VHLYN FITFN GYDNH TYKLYU 
G SSIPTK KYRLE UGFGN LENTYST EXKPT 
H NFMEQ HVHTH TPNGS aTEBY puVvGw 
JT XXXHK PYDNG WAHXK TFKXV ITYHUG 
K NVGUU OYDHY YDNLU SKY YU GT KTX 
L YXPHY NFYDN KWNKCI GNUOP NTNGH 
M JOLOKH TPHTF KUSNHU ODKAP HTNGCH 
N JXBSK IT KYHG EUMKN GCGENGK XHKEY 
P DNLUI VAUIS FOHZH MNNTK SVUKK 
Q KMINI TINXKX PNING HILDH TPDKTI 
R NV¥TIKH TPDUY DWHFN FOUGS NGAHG 
S JUGFU OSHTL DIGKH DHFOU GSWFH 
T THI TK RTLWHA KYDYD NLUSS ITKKY 
U JNHFN GKONA HRXXIV VUXNF YUMNO 
Vo KPDYK TPBXI LOHTH JS KHT LNYODWN 
W XNUMX NGZ2NG XFNLGI HGUYPFU VNTNP 
X IVAGN FGEGUVUIY NOGUS SUXKLU AYUTY 
Y GYOuHT FLNTY GHIJLTD KTHB 


Figure 13~34 (C). Ciphertezt reduced to monoalphabetic 
terms (U). 


(2) By compiling the individual frequency 
distributions using the same method as was used to 


13-23 


CONFIDENTIAL — 


convert the text to monoalphabetic terms, a uni- generated which in effect is merely a tabulation of 
literal frequency distribution for the text can be the former five. See figure 13-35. 


THAT THAT EH AE TP 1 


= HH 
oft 


SHH TTI 

SHRP AA TT 
TAHT TH THI 
<IHAMLII 


=x 


CTL A TH 
batt Il 

OPAL HLTH HEH 
esTA THA TI 
Se] 
“ALRITE 


=H 
>A HATE TH HT 


> THLII 

OTL 

alll 

SHAUL THT HH 
THT HAA | 
vot THY Tt 

cof TH THU 


75 3317 25 36 54 17 21 38 22 8 69915 2319 48 38 12 86038 39 3 


Figure 18-36 (U). Uniliteral frequency distribution of monoalphabetic terms (UV). 


e. Subsequent analysis of the cryptogram is 


ee as 5 10 15 20 25 
now quite simple. The text converted to uniliteral . . ; 
terms can be attacked through an analysis of idio- A. TEER RE ee ee PI@A @JPET 
morphic patterns, repeated digraphs, trigraphs, etc. B ICPMH BCMBD KZPVZ WPABER QI ELE 


In the course of determining the correct cipher 
equivalents for the pseudoplaintext, in this case 
alphabet 1, the mixed-plain component will be D NELAY AVFUY BILYX JPQJE WEKAY 
found. With this as a base, it only requires that 
the cipher components and plain components be ; ee aber 
juxtaposed to produce the values shown in each KF SANE OTR NV CTA AEE Ze ee 
distribution; the process resulting in the reproduction G ITHRGP JEGEC MWAXT JHDVZ TZRWK 
of the enciphering matrix and the keyword. 


C BCIFM IJKFSC TZPFOD UHSEE HECIA 


E ACMBU WEGGG KCKGD 2FEBT ICPPA 


H NQPOA KEAFQ QZ0UM QUIT ICI 
13-19. {\) Application of Principles—Matching I VKRGOD VPECKX NUUVAM WENRWA UHKEG 
a. In the foregoing paragraph the example in- K JPUCQ VERYX JULDE TYQEG HKRRGI 
volved the use of a standard sequence as the cipher 
component. In this example a mixed sequence is 
used. It will be observed that irrespective of the M oYKZGC EPRCB JPUNG NMKIIC RHHAA 
type sequence used, the principle of matching may 
be applied if the cipher sequence isknown. However, eee 
‘if the cipher sequence is unknown, these principles HE SR Ve Boba EG ee A ee eS 
cannot be applied. Q WBABFP MCPXC TQEGY RODAK QHPKE 
b. The first step, as in all cases of the analysis of 
polyalphabetic ciphers, is to underline observed 
repeats and tabulate intervals and factors as shown 
in figure 13-36. 


L Q@GOEZ IVPFd EHLDE THUKE BHAI 


N Q@DPWF ZGAFH WEKEC WRPEG ZP@As 


R ICMXX 


Repeats Interval Factors 

c. The derived factors show that the period ; 
involved is probably five. Since the text is in groups a : : : f Hi 2, 4, 4 10 i 
of five, its rearrangement is not required. Now, MBODK 110 5, 10, 11 22 
assuming that through preknowledge the primary Mei De ie 25 > 
cipher component is probably a keyword mixed _ Figure 13-36 (C). Period determination (U). 


13-24 GONFIDENTIAL— 


-GONFIDENTIAL — 


alphabet based on the word PURLOIN, five separate 
distributions using this mixed alphabet are prepared 
(fig. 138-37). 


Alphabet 1 


= ZZ-= = =ZEtZ? F=Z_-= 
dL PURL INABCDEFGHIKMQSTVWKY2 
-12--7723--2--39479-536123 
Alphabet 2 
= Zz = == 
Z=_ a 7-Z2Z--227=- =. = 
2: PURLOINAB CDEFGHVY KUQSTVWXYZ 
831+-2-1113272295732--21-+-148 
Alphabet 3 
a _ =... 
zE_ ~#==== Z---E2-- -~2#E_ a = 
3: PURLOINABCOEFGHIKUQST AYZ 
217434262224 22-15941---1-2 
Alphabet 4 
— — ~22#22225222 32 _=_ === 
4 PURLOINABCDEFGHIKMQSTVWXKY2Z 
1-1-1596833756-1321212233- 
Alphabet 5 
Seo tee =2=27=2E2Z= == = _ZFEE 
5% PURLOINABCDEFGHI KMQSTVWKY2 
22~1-+--38 27534473-32-+-3-i1744 


Figure 18-37 (@f. Uniliteral frequency distribution of pertodic 
cipher alphabets (U). 


d. Visual inspection shows that the profile of 
each one is similar. The next step is to aline the 
alphabets to bring the peaks and troughs of each into 
conformance. Normally this is a step by step process. 
Two alphabets are selected and juxtaposed in what 
appears the most probable alinement. Note the 
possibility that any one of 26 juxtapositions are 
possible, but consideration of profiles immediately 
limits this to but a few. In this case three possible 
initial matches may be considered (fig. 13-38). 


e. Of the three most probable matches, match 3 
seems best so it is selected. Using these two alpha- 
bets as a base, the third alphabet is compared, 
again in several probable positions, until one is con- 
sidered best. Thus in turn all alphabets are matched. 
The result of the process is shown in figure 13-39. 


Match 2 


Match 3 


ae) 


Figure 13-38 


Alphabet 


Alphabet 


Alphabet 


Alphabet 


Alphabet 


w 


5 


Alphabet 1 
hey. CGE es | ior Se ee ee eS 
URLOINABCDEFGHI KMQSTYWKYZ 
L2--7723--2--39479-536123 
Alphabet 2 
= — 22275 = = ~~ ~=#2-~222 
QSTVWXKYZPUPLOINABCDEFGHI K 
2--21-+-14831--2-1112722957 
Alphabet 1 
= Z#Z-= = = Z=z Zz Zz = zZ— == 
URLOINABCDEFGHIJKMQSTVWKYZ 
12--7723--+-2--39479-536123 
Alphabet 2 
#s_ = ~~ _=#2==272%=-= =- = 
PURLOINABCDEFPGHISY KMES VwkyY 
831--2-11127229573 2-++2i-1 
Alphabet 1 
URLOINABCODEFGHSI KNQSTVWAYZ 
12--7723--2--39479-536123 
Alphabet 2 
_= z= = = = 
=— a ee — ene 2=-2-=-2727=— 
VWKYZPURLOITNAB CDEFGHIKMEAS 
21-14¥831--2-1113272295732- 


(Z). Possible matches, periodic cipher alphabet 1 


ws calf 


We TTI 


and 2 (U). 
PURLOTHABCDEFG 
Se e5 PT 29 me ees 
TVWXYZPURLOISGA 
~-21-+-1214%831-+-+2-1 
EPCOHIKHGSTVWXY 
h22-+15941-+-+-15 
HQSTVWXYZPURLO 
21212233-1-1-1 


Figure 13-39 GP. Final match of periodic cipher 


alphabets (U). 


“CONFIDENTIAL 


13-25 


—GONFIDENTIAL— 


f. If the columns of letters formed by the match 
are inspected, the repeating key ‘““THIEF” may be 
observed, which lends credence to the match. More- 
over, this might be the point of juxtaposition of the 
cipher alphabet to Ap. Unaware that the plain 
component is a mixed sequence, the analyst arbi- 
trarily presumes a direct standard for the purpose 
of reducing the ciphertext to monoalphabetic terms. 
Thus Ap equals Pc, Tc, Ec, Mc, Qc; Bp equals Ue, 
Ve, Fe, Qe, Sc; etc. A standard alphabet is inscribed 
above the matrix shown above, and it is used to re- 
duce the ciphertext to monoalphabetic terms. The 
reduction produces the text illustrated in figure 
13-40. 

g- Compiling the individual frequency distribu- 
tions, a uniliteral frequency distribution for the 
text is generated (fig. 13-41). 

h. Inspection of the text reveals the initial idio- 
morphic pattern. - 


ABCBA BDEB 
C FPA PF PV XP L 


Which may be a reflection of the underlying plain- 
text-REFERENCE; which may be part of the 
phrase “REFERENCE MY (YOUR) MESSAGE.” 
If this is correct Pe would equal Ep, an assumption 
warranted by the frequency shown for Pe. With this 
an entering wedge, the plaintext and accompanying 


"TATA TH 
© THOTT 


S32 
8 6 


© THEAHIIII 


5 10 15 20 25 
A FPAPF PVXPL SHFTP GGUBP SVPRC 
B FPPAW IPGRS QFPEH WGWERW SVGAW 
Cc LPUVZ PWECR UFPVYS RUIUW GUYOP 


D GRSQG HBBPG RESHEF PGHYT WREFeCE 


BE HPGRI WROWV QPFWS &ESARC FPPIP 


F PVGGR SQVPJI GHYDP KEGRS QWTEP 


G FURWI PRCUR PCWGC PUZEH UFRPFP 
H GYPNP QRWVA SFTP2Z SYUOO FREHW 
I GWRWS VGASF GHQQ0 WPGFP BUFZO 
K PGGSA VURHF PXSTT YVEHUV RWRLE 
L STTUH FBPVX LXSiT UUVEU TUWCH 
M YWOWR LGRSQ PGGPV RWUOR CURQE 
N SQPFU ZTWVW GRFUR WIPUV 2CGHGSE 
P OLKEU VVPOG YPHPW OWNWw PE RSALK 
Q WOWRU RPPGR UYOWG CPZQF SAP SG 
R FPGXX 


Figure 13-40 A. Ciphertert reduced to monoalphabetic 
terms (U). 


cipher-to-pseudo-plain equivalent, figure 13-42, can 
quickly be found. 


ro TATTLE THF 
© THINIHL 

oO THUAN 

co TROT 

ra THIET 

TAAL 

< TAATNMLILI 

= THUAN 

> THLIIII 


< THI 
ew THT! 


1015 25 311663 -61 2 14 51 15 36 23 11 30 19 3297121 
Figure 13-41 (U). Uniliteral frequency distribution of monoalphabetic terms (U). 


13-26 


hy og 
NW Bi 
m hy 
‘ B 


Qn NI |S 
Ye WA ue wh 
HNO 
aH Ot 


mC 
q) 01 


Wa 
a) 
Qn 


Plain 


Pseudo-plain 


QP ty td 
Rh hy 


wa 


gn 


YE QH NYU ZH YD 
ma UE N< Vet 
we ZH we se 


=H 
wH 


V 
V 


ros) 
NO 
& 'd 


FGH 
ABC 


JQ 
DEF 


mca 


Qn 


Ke bd 


ac 


Plain: 


Cl: 
C2: 
C3: 
Ch: 


C5: 


L 


HO 


hy og 


W 


NE WH FH 
Qn 


NO 
NO 


Cc 
x 


Y 


wh 


KLE 


JKILMNOP 
Figure 18-42 (Qf. Solution of ciphertert (U). 


e 
Q 
Pp 
Q 


‘yg 


=H 


Ir 
R 


ya I hy hg td Qn ‘yo &I 


HNO 


om a aw HA 


by O "O tA 


cM 


=H 


bt 'y 


cc } 


000 etc. 
000 etc. 


N 
V 


Ics 
WX Y 


D 
vA 


KLEPTOMANICBDFGHJQRSUVWXY2Z 
A eal tel aia ae ea 
eee ee ee vere) eRe cee 
eee ee eral eae ay sale 
ee ee AISA ee 
laalale|ole[e| ol elo [xlua|s|e| le x|z|2l ella slo 


_ Figure 13-43 . Recovered matrix (U). 


1. In the plain sequence the keyword KLEPTO- 
MANIC is observed. By using it then as a base with 
Kp as the index letter, five cipher sequences may be 
inscribed below it to reproduce the original encipher- 
ing matrix. The juxtaposition of each of these 
sequences must be used to reproduce the original 
ciphertext. That is, the letter Ep when enciphered 


by the five successive cipher alphabets must result 
in Je, Ce, Pe, Ne and -Ac respectively. Although any 
plaintext letter may be used for this alinement 
process, Ep was chosen because of its frequency. 
Thus the folowing matrix is reconstructed, figure 
13-43. 


13-27 


CHAPTER 14 (Cf 
INTRODUCTION TO SIMPLE APERIODIC CIPHERS 


Section |. (ay SIMPLE APERIODIC SYSTEMS 


14-1. (oS Introduction 


a. It was demonstrated in the preceding chapter 
that the ordered use of a number of alphabets in 
periodic ciphers resulted in the occurrence of cyclic 
phenomena in the ciphertext. It was also shown how 
this cyclic phenomena could be used as the basis 
for the cryptanalysis of the cipher. This was true 
even though a greater number or different types of 
mixed alphabets were involved. The significance of 
this phenomena was recognized by cryptographers, 
and means of suppression were soon considered. Two 
basic methods of suppression are available. First, the 
cyclic phenomena may be avoided simply by extend- 
ing the key length to such 4 point that it repeats 
itself only a few times in a given message, and 
second, by the key length extending indefinitely, 


forming a running or continuous key. This particular . - 


solution, however, is impractical for use in all except 
machine systems. For this reason, and because the 
analysis of continuous keyed systems involves 
techniques and methods beyond the scope of this 
manual, it will not be treated further. 

b. An alternate scheme, which permits the use of 
a matrix or table similar to those of the periodic 
ciphers, is to vary the period of key usage and thus 
suppress cyclic phenomena at the outset. Considera- 
tion of why periodicity is inherent to periodic 
polyalphabetic ciphers reveals that it is composed of 
the two elements involved in its production. That is, 
successive letters of a number of alphabets controlled 
by a repetitive key are applied to successive letters 
of the plaintext. Thus, if either of these components 
are varied, an aperiodic system is generated. Note 
that in aperiodic systems cyclic repetition does occur; 
however, it does so at an irregular interval which 


serves to suppress its appearance to a greater or 


lesser degree in the text. ; 

ec. Aperiodic systems then may be arbitrarily 
classified by the cryptographic method used to 
develop their aperiodicity, that is, by those compo- 
nents selected to vary and those selected to remain 
constant. Thus, those systems where the plaintext is 
made variable and the key sequence held constant 


may be considered as one class, and those systems 
where the plaintext is held constant and the key 
sequence used variably may be considered as another. 
Note that the resultant ciphers produced by either 
method are similar in that they will yield to the 
same general technique of analysis. 


14-2. (2 Methods of Variations 


a. One method of introducing variation in the 
plaintext is by word-length encipherment. In this 
method the key is applied in its sequential order to 
successive words of the plaintext, i.e. the first word 
is enciphered from the first alphabet, the second 
word from the second alphabet, etc. In this manner 
the key is completely run through, its cyclic reuse 
beginning anew following the use of the last alphabet. 

6. One practical difficulty involved in decipher- 
ment of messages of this type by cryptographic 
personnel was in recognizing the end of a word, as 
in the case of INFORM, INFORMS, INFORMED, 
INFORMING, and INFORMATION. This led 
to the inclusion of a word separator. The word 
separator was used to mark the end of a word (the 
resumption of the keying cycle at its initial point), 
thus aiding the deciphering clerk. A low-frequency 
letter was selected to be the word separator because 
it was necessary to preclude the possibility of 
interrupting the keying cycle at the wrong position. 
The letter selected as a separator (J or V for example) 
was often excluded from the enciphering matrix, 
this being essential to avoid ambiguity in the 
decryption. 

c. This particular method suffers from an obvious 
fault. Since successive. words vary in length in an 
extremely irregular manner, the process then results 
in the destruction of obvious periodicity. Note that 
individual words are being enciphered in) mono- 
alphabetic terms. Thus, solution is quite simple. 
If standard alphabets are involved. completion of 
the plain component will lead to an immediate 
solution. If, on the other hand, mixed alphabets 
are used, idiomorphism remains and provides a 


relatively. easy entry. 


-CONFIDENTIAL— 1 


CONFIDENTIAL — 


d. In those cases where idiomorphic patterns are 
not obvious, the word. separator may be used as 
an initial entry. A word separator may be either a 
plaintext value or a cipher value. The plaintext 
value will be enciphered and somewhat more difficult 
to recognize. If, however, it is a constant cipher value, 
it should be readily apparent. In either case, once 
isolated, word separators serve to distinguish indi- 
vidual words, thus providing a basis for analysis 
through a study of the uniliteral characteristics of 
the words. 


Key ; re a 4 5 6 
Group i <2 3 4 5 1 
P C OM MAN DING GENER A 
Cc Q@ UW UGT KFAH UWNWT L 
Key 5 6 1 2 3 4 
P S SU EDO RDER SEFFE C 
Cc I TR OPE RFER OCBBC L 
Key 3 & 5 6 1 
P T AT WOO NDIR ECTIN 
C N NU WMM YIDU OQZKF 
Key ae 4 - 
P C OM MAS WITC HBOAR 
Cc @ UW UGO RFUL ictal 


Cc QUWUG TKFAH UWNWJ LHNAR 


OCBBC LHSQH SWOFZ KDARQ 


UWPWL EXYHT QUWUG ORFUL 


WoO AAD 


3 retetetetotetalate ete terete tetetete tea pete 

yinimiztk|s|riagigiFleiolcipialz{yi|xiwi[yi[ulri{s | 
fAlZ|¥ixiwiviul|7Tisiri@iPlo|wimizixis{[rlalelrie lo 

OlLiK|yirIe|GiFlel(olci|Blalz{yixiwi[viyirisiRi[@iPlo ly | 


14-3. (2) Numerically Keyed Encipherment 


a. Another method of varying the plaintext is 
by using variable plaintext groupings which are 
not successive words. In this method the plaintext 
is divided into segments of predetermined lengths. 
Again, in the encipherment process, one alphabet 
is used to encipher each group. The key cycle of 
encipherment extends through a number of groups, 
then begins anew at its initial point once one key 
cycle is completed. Group length may exhibit a 
patterned regularity as shown in figure 14-1. 


i. 2 3 4 

2 3 4 5 
LF IRS TARM YHASI 
HN ARQ GPU PGNVF 


5 6 1 2 
TI VET WENT YFIRS 
HS QHS WOFZ KDARQ 

5) 8 5 6 
TH ATT ELEP HONES 
NZ NUU WPWL EXYHT 


1 2 000 
SC OMM 000 


AQ UWW 000 
AR _QNGPU PGNVF ITROP ERFER 


‘wNUNM MYIDU OQZKF CwWZNU 


TZMAT IAQUW W... 


Z vaea 


Figure 14-1 (G). Encipherment by arbitrary group length (U). 


142 __CONFIDENTIAL— 


CONFIDENTIAL — 


Group length may also be varied, the key of the 
matrix is used for this purpose. For example, assum- 
ing a keyword TRACK, a numeric key of 54123 
can be generated. Thus, the text would be divided 
into groups of 5, 4, 1, 2, and 3 letters, the cycle 


Alphabet Key 1- 2 3 
Group Key 4 1 


C QEGGS FAVC A 


b. The example in figure 14-1 serves to illustrate 
one of the faults of arbitrary group division. In 
theory, when the keying element is kept constant 
and the plaintext groupings are made variable, 
even though the key is used cyclically, external 
periodicity will be suppressed. Note that when the 
plaintext grouping contains similar letters, and when 
the cycle of variable grouping is applied several 
times to the message, periodicity can occur. The 
two occurrences of QUWUG illustrate this point. 
They are separated by an interval of 90 letters; 
their plaintext letters, their group size, and their 
key letters are the same, thus they constitute a 
true periodic repetition. Also of interest is that 30 
groups intervene. Since the length of the key is 6, 
the cycle is repeated 5 times; thus, in the case of 
true periodicity, the interval of 90 is the product of 


5 
Pp COMMA DING G 


being repeated throughout the message. Encipher- 
ment would then follow the same method of en- 
cipherment as shown in figure 14-1 above, each 
group being enciphered by one alphabet. For 
example: 


4 5 6 1 2 
2 3 5 4 l 
EN ERA LFIRS TARM Y 
JA WJA AGDUT ZSBG K 


the total number of letters in the key multiplied by 
the number of cycles of the key. 

c. The repetition of ARQN is of another type, 
termed partial periodic to distinguish it from the 
former. In this case the interval is 39 letters. It is 
true that this repetition involves similar plaintext 
values IRST, but involves different evclic group- 
ings. Note also that the points within the two group- 
ings are different. In the first case the repetition 
begins with the first letter of group 3 and ends on 
the first letter of group 4. In the second appearance 
it commences at the third letter of group 5 and 
ends on group 1. However, it should be observed 
that the number of key groups intervening between 
the two repetitions (twelve), is the product of the 
maximum number of key groups (six), multiplied 
by the number of repetitions of the key (two). 


Section Il. ( SOLUTION OF SIMPLE APERIODIC SYSTEMS 


14-4. (4) Solution of Numerically Keyed Enci- 
pherment 

a. Solution of numerically keyed encipherment 
follows essentially the same step as that shown in 
the preceding example regardless of whether the 
individual groups are of increasing length through 
the cycle or are irregularly mixed. Initial identifica- 
tion of the system may be somewhat difficult, its 
- recognition resting largely on two characteristics. 
First, any uniliteral distribution of the ciphertext 
will be relatively flat, similar to a periodic system. 
Second, it may be distinguished from a periodic 
' system in that observed repetitions will not factor 
evenly in all cases. Moreover, in a long message 
enciphered by either system there are usually many 
repetitions of both types so that identification might 


468-095 O- 72-14 


hinge on the availability of outside information to 
determine the basic system. 

b. Once the system is recognized, analysis may 
take one of two courses depending upon the alpha- 
bets used. Where the system involves either the use 
of standard cipher alphabets or known mixed cipher 
alphabets produced by the sliding of a mixed com- 
ponent against the normal sequence, solution may 
be accomplished by completing the plain component. 
In such cases bits of plaintext will be found on 
several different generatrices. The number of plain- 
text letters appearing successively on one generatrix 
is the same as the number enciphered at one setting 
of the numerical key. This is illustrated in figure 
14-2 which shows the completed plain component 
and its accompanying matrix. 


14-3 


c BODOKTHCBMIUYHVTMBHFSUGFEFRT 
CELUIDCNKZIWUNCIGTMHGSU 
DFMVJEDOLASJXVODSJHUNIATYV 
EGNWKFEPMBKYWPEKIVOJIUW 
FHOXLGFQNCLZXQ@FLIWPKIJVX 
GIPYMHGRODMAYRGMKXQLKWY 
HIJQZNIHSPENBZSHNLILYRMLXZ 
IKRAOTITFTQFOCATIOMZSNMYA 
JLSBPKIJURGPDBUTJPHATONZB 
KMTCQ@LKVSHQECVKQOBUPOQOAC 
LNUDAMULWTIRFDWLRPCVQPBD 
MOVESNMXUTGSGEXMSQODWRQCE 
NPWFTONYVKTHFYNTREXKSRD 
OQ@XGUPOZWLUIGZOUSFYTSE 
PRYHVQPAXUVIHAPVTGZUTEF 

B 
Cc 
D 
E 
Numerical Key 4-3-1-2-6-5 
POINTS 
P ABCDEFGHIJKLMNOQO UVWXYZ 


on CBTST RLS roy wee a To ee Toe ee) 
c2 poletatelstetut rial xe tla talc to tete bot r ta et 
c3(_z[v{xiz[MiwlolPla@la(si7iyiviw[x[y[ztalaiciolel Fy 
ch BIDE OAn Era aO eae 
c5 | riul viwixty| 2) [elrletaiziatx[zim[vfolelelris | 


- BEL UUWE UWE uaa eb ecaiatadil 


Figure 14-2 (GQ). Numerically keyed encipherment, standard 


alphabets (U). 


c. In the case where the primary components are 

a mix of known and unknown sequences, solution is 

possible through the application of idiomorphism 

and the principles of direct symmetry of position. 

To illustrate the methods involved in this approach, 
the message in figure 14-3 will be used. 

(1) A brief inspection of the ciphertext reveals 

the sequence HZNZHZ, which is significant under 


5 10 415 20. 25 
A  H2NZH ZPDAF RZVPB X2ZLCA QBoOBY 
B -RBIGH IIMAR UHBJB YTWVX RsyRT 
C  XAKWH VHQQE IMMXZ DDWKG YPXFT 
D  -EJFQP VUXRV ABVGC VXQRM BXUGB 
E  LRDDS LXBAE AFAZQ PAVIC MBAIW 
F  KVHQP 


Figure 14-3 Wi . Aperiodic cipher message (U). 


two conditions. First, the cipher is numerically keyed; 
the possibility exists that this sequence is the product 
of the application of one key, the number of letters 
enciphered corresponding to one setting of the key. 
If this is true, it represents a period of monoalpha- 
betic encipherment and the idiomorphic pattern 
ABCBAB may be used in assuming a plaintext word. 
Second, if a known sequence was used as either 
component, direct symmetry of position can be used. 
Assuming both conditions to exist, a list of idio- 
morphic patterns is searched to locate a word which 
matches the pattern derived. Among others, the 
word REFERENCE is noted. This is an ideal word 
for opening a message. Then, assuming a standard 
sequence was used for the plain component, the 
following preliminary matrix may be set down: 


P ABCDEFGHiIJKLMNOPQRS TUVWKRY Z 


eae) 


(2) Thus the above results in the following 
plaintext insertions: 


5 


LEE ET Ed 


| | | 

| po 

ba ae | 
| 

i | { 


10 


A C HZNZH ZPDAF RZVPB XZLCA 


P REFER ENCE 


Lgdisaits REFERE should be expanded to REFER- 
ENCE, thus providing additional equivalencies. The 
problem that arises, however, is the determination 
of the length of the group, i.e. how far does mono- 
alphabeticity extend in this case. A consideration of 


14-4 


the word itself reveals that it must break between 
A6 and AQ, for the last Ep value at AQ is dc and the 
last repeated monoalphabetic bit is Ep=Ze at A6. 
A second cipher component, when Np= Pc, may be 
inscribed in the matrix: 


—~CONFIDENTIAL— 


P Thee TIT lillie 


c -_ dele LLL 
a 


PLL 


(3) At this point the question of what would 
be the most profitable method of attack must be 
considered. Should we expand the plaintext, or apply 
the principle of direct symmetry of position? Perhaps 
the two can be incorporated. But first, the matrix 
should be examined. Note the occurrence of the Ze 
and Ne in adjacent positions in cipher alphabet 1. If 
the initial word assumption is correct, the cipher 
component is not a standard alphabet. Mixed 
sequences may be derived by decimation, keyword, 
transposition, or by random methods. However, if 
the cipher sequence is keyword mixed, Ze Ne is 
significant in that it may mark the end of the sequence 
and the beginning of the keyword. The letter He 
appearing 12 spaces to the right may represent, in 


5 
A Cc 


(—_|_———! 


in ce eee 
a. 
bee dee! oe eer eee 


ee 
PEEL 


this case, a portion of the sequence where alphabetic 
sequencing is resumed; its distance from Ne makes 
it improbable as a part of the keyword. In any case, 
if each successive secondary cipher alphabct is but a 
different juxtaposition of one basic sequence, then 
the principle of direct symmetry of position will 
apply. But to be used, the same letters in several 
alphabets must be found. 

(4) Perhaps such a hit may be discovered by 
expanding on the assumption of the plaintext. The 
assumption of the word REFERENCE should 
lead to the further assumption of the phrase REF- 
ERENCE YOUR MESSAGE, or REFERENCE 
MY MESSAGE. Neither may be right, but they 
are worthy of consideration until proven untrue. 
Accordingly, the following may be inscribed: 


TILL 
FCCP 


I 


{ ! 
| 
i | 


10 1 5 20 


HZNZH ZPDAF RZVPB XZLCA 


P REFER ENCEY OURME SSAGE 


P ABCDEFGHIIJKLUMNOPQRSTUVWXYZ 


; TTT 
: PT 
C3 

ch 

cs 

c6 

CT 

c8 

cg 

clo 

cu 

cle 

c13 

a PUUEANEEINEMA 

as OMEPERERROREOEREER 


Figure 14-4 —. Expansion of matrix (U). 


Using the equivalencies, the matrix may be ex- 
panded further. However, each letter must tempo- 
rarily occupy ® separate horizontal line because the 
points where the keys are changed are unknow1w 
except in the case where SSp=.XCc. Thus, the 
matrix would appear as in figure 14-4. 

(5) Several interesting patterns indicative of key 
changes may be observed in the matrix. First is 
the assumed value of Sp for Xe and Ze in alphabets 
11-12. If the assumption is correct, then this is a 
point of key change. Note also that there are four 
values for Ep shown, Ze in alphabet 1, Ac in 4, 
Be in 10, and again cic in alphabet 15. Thus four 
key changes are indicated in a period of 15 letters, 
one period being a repetition of another in respect 
to the point of juxtaposition. Moreover, He in 
alphabet 1 and Ve in alphabet 8 are noted as equal- 
ling Rp. On the basis of these patterns an indication 
of the periods may be shown as follows: 


C HZNZH Z/PDAF RZ/VPB X/ZLCA 
P REFER E/NCEY OU/RME S/SAGE 


14-5 


-GONFIDENTIAL- 


It must be understood that this delimitation of 
periods is arbitrary, only serving to limit some 
possibilities and providing a basis for either proving 
or disproving previous assumptions. 

(6) The matrix may now be rearranged in 
order to compare the patterns (fig. 14-5). 
P STUER TT 


cl 


Examination of alphabet 2 shows the Zc followed by 


= CURMCITETTCT RATE] Be Ba eral o's fd 
c3 ELT eee pkabeus alone: fe abe é ‘o See 
the beginning of the keyword, th lues th 
eee AEE DEE ee ee 
Figure 14-6 ph. Matriz reduction (U). the principle of direct symmetry of position: 
P ABCDEFGHIJKLMNOPQRSTUVWXYZ 
Pe Pe ae ke a ie ee ee a 
C1 | | | | 2 
| i | 


This leaves the occurrence of the sequence PRe 
as equivalencies of the sequence NOp in alphabet 2 
to be explained. It may be possible that Q is part of 
the keyword, for where else could it appear in light 
of the assumed PRe sequence? This placement is 
unlikely. Therefore, the sequence in this position 
may be incorrect. Moreover, note that the Pe=Np 
equivalency appears in the initial reconstruction 
matrix prior to the Re=Op equivalency in cipher 
alphabets 2 and 6 respectively. Therefore, they may 
not have been drawn from the same alphabet. In 
this case Qe could have come from a preceding 
alphabet. If so, it would fall prior to He, out of 


P ABCDEFGHI 


' 


Cl | vix r| 


By maintaining similar spacing Bc may also be 
placed in its proper position relative to Ac. The 
Pe now falls into proper sequence. 

(8) This leaves only the fourth sequence to be 
fitted, which appears to be quite easy as Ac and 
Ze have been placed. However, when the fitting is 
attempted it will be found that the sequential 
relationships are incorrect. Counting from Zc to 
Le an interval of 8 is noted, thus placing Le below 
Mp, in the protosequence, and adjacent to <Ac 


P ABCODEFGHI 


Cl 


sequence except as a part of the keyword. This does 
not seem likely, so it may be set aside for the moment. 

(7) The third alphabet may now be considered. 
Four spaces, normally occupied by the letters 
QRSTU, are observed intervening between the 
letter Pe and Ve, although no space is noted between 
Ve and Xc, which is usually occupied by the We. 
Perhaps the We and one of the letters RSTU (Q 
being discounted) may be part of the keyword. 
Assuming that in the unknown cipher sequence that 
Xe and Ye will precede Ze, this sequence can be 
incorporated into the sequence thusly: 


a 


cn oe 
el Se 


A 


al 


| 


| 
| 
| 


below Np, yet Le and Ac are separated by one space 
in the fourth sequence. Referring to the ciphertext 
with its assumed plaintext shown in (5) above, it 
is observed that the equivalancies of Ze and tc are 
separated by the Ce=Gp equivalency. This in- 
consistency may be explained by another key change, 
Ze, Le, and Ce from one alphabet and Ae from 
another. Accepting this for the moment. it is found 
they can be fitted, thereby retaining the previously 
established sequence. 


JIKLMNOPQRSTUVWXK Y Z 


iar 
eae 
| 


ied 


| 
ai 


14-6 ~GONFIDENTIAL— 


d. With the partially recovered cipher sequence, 
the recovery of the matrix and decipherment of the 
cryptogram may be started. This is a simultaneous 
effort, and the values found are transferred from one 
to the other. First, a matrix which will produce the 
correct plain-to-cipher equivalencies for the as- 
sumed plaintext is constructed. A separate strip is 
prepared for each period of use, as shown in figure 
14-6. Note that in so doing Re can be placed in the 
third sequence, a value which is immediately trans- 
ferred. Also, because of spacing, Qe is inserted and 


transferred. 

P ABCDEFGHISKLMNOPQPSTUVUXY2Z 

$35 CPR PP 

3 C2 1) At the fifth period it i iscov 
res (Dzlaact al ere Peete rr Selina oe ge ered oe 
> Ch elalaicl at etal err ee further decipherment using the juxtapositions found 
2 cs Cl porelarerer Tal TTT Tepore tT Tv 2a TF is no longer possible, thus another key change for 
Kay 1 2 3 a an undetermined period is indicated. In this case 


Group 6 be: is ab two sliding strips should be constructed to test the 
A -H2NZH «APDAF = RZVPB feuca QBOBY PBIGH ‘ : ; eee ; 

REED. HiCES: “CURIE. cae OF assumption of possible words, keeping in mind that 

one juxtaposition will render plaintext for an un- 

determined number of letters. In context with the 
C  -VHQQE =“IMMXZ DDWKG YPXFI EJFOP assumed plaintext it seems logical to expect a time 
reference to follow. Accordingly, the words ZERO, 
ONE, or TWO may be assumed. The strips are 


B IIMAR UHBJB YTWVX RSYHI XAKWH 


D VUXRV ABVGC VXQRM- BXUGB = LRDDS 


E  -LXBAE AFAZQ PAVIC MBAIW KVHGP then juxtaposed to produce the required values. If 
Figure 14-6 . Partial matriz and recoveries of the assumption is correct, then all assumed. equiva- 
plaintext (U). lencies- must match. 
P ABCDEFGHIJKLUMNOPQRSTUVWXYZABCD 
| | 
Cc | piz|al aie H | | | P|Q|R | fy) x)rle|y | ple Bek 4 
Heo ited | ee ee, 


(2) After a short period of experimentation 
the strip above will be found which will produce the 
assumed ZERO plus the letters E--H. This con- 
firms the ZERO assumption and E--H possibly 
represents the word EIGHT. Accordingly, the cipher 
values can be inserted in the matrix (fig. 14-7) 
which would now appear as: 


P ABCDEFGHIJKLMNNOPQRSTUVNXY2 (3) Observation of the periods used show that 


hey are 6—-3-7-2-4~8, thus key periods 1 and 5 are 
as BGGREURRGOEREOUGGOGRee x siiane also possibly 9 and 0. A glance at the cryp- 
BIC COOGOGONNNGOGNTECEH 
7 93 i eae ele eee 


togram reveals that the groups JJMfik UHBJB 
immediately follow that which gives ZERO EIGHT. 
Then, where Tp of EIGHT equals Jc, the second 


is) 


BS felalafeleledz] | felelel | [elle lela] | [elel fo) Ic must also equal Tp. Therefore, this period could 
4 C5 rt toatetetabt tT tab tap ett P be five. In any event, it can quickly be determined 


by alining the two sequences so Jc equals Tp. In so 


8 c6| |p clel# R 1 
{ Tolelalshelelel2] Lt elelel | ieledeletel | doing, Wp is found to equal Me. The matrix may 


Figure 14-7 (Qf. Insertion of cipher values (U). now be transcribed as shown in figure 14-8. 


—GONFIDENTIAL— | 14-7 


—-GONFIDENTIAL— 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


rea Joe] ct Th 

soll | motel Lee tal | tel 2 
« e5}o} [olelalalel ofall | Petelal | [yle(rielal | | 
0 es{ [olclalelelolalz] | [alelalal | [vielzielal | | [ 
ser] | Velelefelal | Jefol felelalalelelalz] | [mlelele 


Figure 14-8 fp. Transcription of matriz (U). 


. 


<= 

7 

N 
= 


N FO DLABCGHI 


ER S T U W 


(5) Considered in this light it takes little 
imagination to recognize a probable keyword in 
NEWFOUNDLAND. Accordingly, the values are 
inserted and the matric recovered as shown in 
figure 14~9. Note that a key is recovered which 
explains the sequence of periods used. 


Pe ABCDEFGHIJKUMNOPQRSTUVWXY2Z 
6 Cl 
-3 c2 
7 3 
2 ch 
Wes:G5. 


8 cé 


5 CT 


1 c8 


Figure 14-9 (f). Recovered matriz (U). 


Using this matrix and the period sequence shown, 
further decipherment of the cryptogram is merely a 
cryptographic task. 

e. A very important point is that the solution 
presented above represents but one method which is 
possible only because of the circumstances involved 
in producing the cryptogram. First, the message 
contained a stereotyped beginning. Second, the 
stereotype was discernible in the ciphertext, as the 
initial period of key usage 6-3-7-2 was sufficiently 
long to produce an idiomorphic pattern. Third, the 
use of a standard sequence for the plain component 
and a keyword mixed sequence for the ciphertext 
permitted the use of direct symmetry of position. 
Thus the solution was relatively simple. However, 


(4) The values of TTWOZp for [JMARe, 
derived by alphabet C7 above, provide the clue 
that the juxtaposition of the eighth alphabet in the 
Ue of the group VHBJBe must equal Ep to provide 
an E for ZERO. However, note that no U placement 
exists for the cipher sequence. Perhaps the U place- 
ment may be inferred by elimination from the 
information at hand. In the sequence A —- — V 
above, two spaces intervene which should be occupied 
by either S, T, or U. Obviously, one of these must be 
part of the keyword. Considering each vacant space 
in turn, the following letters can be placed. The 
remaining letters are assumed to be part of the 
keyword. This may be observed in the following: 


JKLMPQ VXYZ 


had one or more of these factors been different, that 
is, smaller key periods, a different cipher sequence 
derived by a more complicated method, or two 
unknown sequences, the final solution would have 
been more difficult if not impossible. A solution is 
possible where the analyst has some preknowledge 
concerning the system, its contents, or operation, in 
the case of small samples. Where this knowledge is 
not available with the information presented to. this 
point, only one other means of solution is. possible. 
That is, through the acquisition of sufficient depth, 
so that values can be played against one another. 
This particular technique will be illustrated in sue- 
ceeding paragraphs. 


14-5, §g) Analysis of Variable Length Keying 


a. The preceding examples dealt with the use of 
variable length plaintext groupings enciphered with 
a constant length key element as one means of 
introducing aperiodicity into a system. Aperiodicity, 
avoiding external periodicity, may also be introduced 
by the reversal of the same techniques, that is, by 
holding the plaintext units constant while applying 
a variable length keying unit. The most common 
method of producing a variable length keving unit, 
where the base keying unit is limited or fixed in 
length, is by irregularly interrupting it. Thus a cyclic 
keying sequence, which would normally produce 
periodic phenomena in the ciphertext, would now 
introduce an aperiodic element instead. 

6. There are several methods which may be used 
to interrupt a normal cyclic key, all of which may be 
classified into one of three general types. The types 
are: 

(1) The keying sequence merely stops at some 


14-8 CONFIDENTIAL— 


-CONFIDENFIAL— 


after each stop. An example of this encipherment is 
depicted below using the preceding matrix. 


point in the sequence, succeeding points differing 
irregularly, and resumes at the initial starting point 


Base Key Sequence 1-2~3-4~—5-6-7-8 


Key Element 123 4 * 12 3 * 12 3 4 5 6 * 1 2 * ete. 
Letter Number 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 etc. 
Plaintext REF E REN CEM YME ss etc. 
Ciphertext HACG HA@Q XA PUMB IV ete. 


again, with different elements dropped by pre- 
arrangement between the cryptographers. This 
method is depicted below. 


(2) One or more elements of the base key are 
dropped irregularly during each keying cycle. On the 
completion’of one cycle the base sequence is resumed 


Base Key Sequence 1-2~-3-4-5-6 


Key Element 23 4 6 125 * 1 3 4 5 6 * 2 3 4 * 1 2 ect 
Letter Number 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 etc. 
Plaintext REFE REN CEM YM ES 5S etc. 
Ciphertext T BHA H A P X BR WP AX Z etc. 


sequence is reapplied in the same manner through- 
out the text. The example below illustrates this 
method. 


(3) The base key sequence is applied to the 
text, alternating irregularly in direction, with or 
without the omission of elements. The base key 


Base Key Sequence 1-2-3-4-5-6-7 


Key Element 123 45 * 4 3 * 4:5 6 7 * 5 4 3 2 1 ete, 
Letter Number 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 etc. 
Plaintext REFER EN CEM Y-. MES 8 A ete. 
Ciphertext HACBT GQ BAP®Q MGXV T ete 


Note that in this method, if no key elements were 
omitted and the key sequence was repeated, it 
could be treated as though it was a 16-element key 
sequence rather than an interrupted system. The 
cryptographic effect of it is the same. 


14-6. og Periodic Patterns in Aperiodic Systems 


a. Although aperiodicity is introduced into a 
system by this method, certain patterns are re- 
tained which, if recognized, may be exploited for a 
solution. The first of these patterns arises through 
the successive use of the same basic key sequence. 
For example, if the analyst knows the points of 
interruption, the several cycles of a given message 
may be stacked upon themselves to produce bits of 
monoalphabetic encipherment. Of course, the longer 
the message the greater the size of the bits, and 


consequently the more useful this method is. The 

stacking of successive cycles to illustrate the bits of 

monoalphabetic encipherment is shown below. Note 

the repeated cipher letters that occur: cach repre- 

sents the encipherment of a single plaintext letter. 
(1) Method 1. 


Key Element 12 3 4 5 6 7 8 
Letter Number 1 2 3 4 
Ciphertext HA CG 
5 6 7 
HA Q 
8 9 10 11 12 18 
Nut PU MB 
14 15 16 17 18 19 20 21 
IV. ete 
22 23 
24 25 26 27 ete 
14-9 


-GONFIDENTIAL- 


(2) Method 2. 


Key Element 123 4 5 6 
Letter Number 123 4 
Ciphertext T BH A 
5 6 7 
HA P 
8 9 10 11 12 
x BR W P 
13 1415. etc. 
AX Z 


(3) Method 3. 


Key Element 123 4 56 6 7 
Letter Number 1 2 3 4 5 
Ciphertext HACBT 
7 6 
GQ 
8 9 10 11 
BAPQ 
16 15 14 138 12 
TV XQM 


Obviously the ability to stack successive sections of 
a message by the successive sections of a keying 
sequence is predicated on the preknowledge of both 
the key sequence and its points of interruption. 
This technique is primarily applicable in those cases 
where past analysis has resulted in the determination 
of the system, its key, and its use. 


6. Other patterns which may occur in systems of 


this type are the familiar idiomorphs. They may 
represent a complete word or a part of a word. 
These patterns arise as a consequence of similar 
portions of plaintext being enciphered by similar 
portions of the keying sequence. Where the point of 
interruption falls on a given word consistently, 
particularly in the case of method 1 above, this 
phenomena is likely to result. For example, note the 
situation in figure 14-10. 


14-10 


123#1234*1234%56... Key 
Message A P RET REAT WILLBE... PLAIN 
C GSB GSIG LWTYUW... CIPHER 
12345*21#123456*1 =... KEY 
Message B P OURAT T ACKWIL L... PLAIN 
C DIZNM I PQSJBOD A... CIPHER 
12*1223456*1234... KEY 
Message C P AT TACKONO URLE... PLAIN 
C PH IPQSBGG VJFFTR... CIPHER 


Figure 14-10 fp: Idiomorphs formed in encipherment (LC). 


Observe that the patterns so produced may be both 
idiomorphic, as 
RETRE 

in the case of the pattern ABCAB for GS BGS in 
message A, or merely repetitions as in the case of 
TACK 
I PQS in messages B and C. Obviously then, the 
usefulness of these is limited by the chance of their 
happening. That is, their production rests upon the 
accidental occurrence of fortunate circumstances. 

ce. A more important pattern, in terms of useful- 
ness to the cryptanalyst, lies in the repeated use of 
the same starting point in a sequence of keying 
elements in a number of messages. Where this occurs, 
monoalphabeticity is present in the columns formed 
when a number of messages of the same system are 
superimposed. Note that the initial sequence of 
keying elements must be constant and that the 
messages superimposed must all be from the same 
system. Also, the greater the depth, the more pro- 
nounced the monoalphabeticity exhibited by each 
column, This is particularly applicable in the case 
of short messages, because the number of messages, 
not their length, is the important criteria when all 
other factors are constant. To observe the signifi- 
cance of this, note the superimposed messages and 
the frequency distribution derived from the first 10 
columns so formed in figure 14-11. 


Letter Number Message Letter Number 


Message 


No. 


dt 

Hm 
AON 
dd 


AONMOHWHEMODRNH 
ANH DQAHADTWHNAN 
ONNA EWE HQRNNHOY 
he AMS OAM N NM NY a & 
WOH RHONN SGU ORR 
INS SR ON BA MQ 


=O 


TOWSON. 
MAF AAQONVBEYANHONHNO SH 
AR, AY se AQ Ry 
HUMNNORMNDWORNON|ANN 


Aaaava 
at 
Ame 
AA ea 
HANA, 
AOA YQRMwTs& 


AWN WeDo 
COR MNS Oy 
hn By 9 
LO ee 
INN FE 


at 


YOR OO fy 


07 By fy RGA RY 


N 
et 


ONO & WN 
N@Qh as 


aN Mt INNO 


hy WQ 
S my hy 
Nh re QQ 


VWVODGHPGUZ 
B 
J 
6) 


We SRAD 


GN MONHOXS 


B 

EB 

vA 
HC@Q@IWSYSBPHCZY 


INO EDAD AN Mat MN 

UAINUANAMOMMMAMNM 
& 

Q Nd 

wn Ae. TR =) 

Soe Ex<BWO & 


PMONNHYNEADQNOIN 


BSHWHRNVWHOANR GOSS 
NHUNMONOEADOEAGDNN 
SRRANHUNN ORAS 
SOBZAHORN LRH S 
UNRAENOOWDAEN 


IHL & 


Letter Number 


1 ead 


| & 


ITJKLMNOPOQRS 


—=—=5 


ABCDEFGHISGKLHNOPQRSTUVWXYa2 


ABCDEFGHISTKLMNOPQRS 


10. 


Figure 14-11 a) . Frequency distribution columns 1-10 (U). 


14-11 


CONFIDENTIAL — 


(1) The first and second distributions are 
certainly monoalphabetic. The peaks and troughs 
are pronounced, and the number of blanks, con- 
sidering the size of the samples, corresponds with 
that expected. But note that the same pattern is 
lost in the remaining alphabets. This may be ex- 
plained by a change in the successive points of 
interruption. 

(2) Assuming that the first, second, and pos- 
sibly third columns are monoalphabetic, the pos- 
sibility of an entry is provided, based upon the 
assumption of probable words. Recall that most 
military messages are prone to stereotypes, particu- 
larly in beginnings and endings. Thus words such as 
REFERENCE, REFER, REQUEST, ENEMY, 
IN, etc., are commonly found. High-frequency di- 
graphs used in the initial portions of common words 
are observable in the first two or three columns. For 
example, in the first two columns above, the follow- 
ing digraphs can be found: 


14-7. (4) Interruptions 


a. To this point, only the results of the keying- 
sequence interruption have been discussed. No 
mention has been made of that element which deter- 
mines how the interruption takes place. For this 
purpose, either a letter of the ciphertext or of the 
plaintext may be used, the exact letter being agreed 
upon in advance. Since there is nothing fixed relative 
to the time of interruption, it will appear quite 
irregularly, exhibiting no distinctive pattern or 
cyclic periodicity. Whether the letter itself is a 
ciphertext or plaintext letter is of no importance. 
Interruption, in the case of a plaintext letter, takes 
place after that letter is enciphered. In the case of 
a ciphertext letter, the interruption occurs after the 
selected letter is produced by the enciphering 
process. 

5. The source of the letter selected for use as an 
interrupter letter is significant in that it may have 
a direct bearing on the solution of a cryptogram. 


ZC-7 WT-3 HC-2 This may be seen in figure 14-12 where the interrupter 

CI-2 AF-2 C L-2 is a plaintext letter. 
Key----- BUS INESSMACHIBUSIBUSTIBUSINE 
Plain---AMMUNITIONFO FIQSTAQTILLE 
Cipher--B OLY RPJDROGKKIKGFIYXSXKiDIUPS Y 
Key-----B US INESSMACHINESBUIBUSINESSMACHI 
Plain---Y WI LLBELOADEDAFT AMMUNITIONFO 
Cipher--I YDPYFXURAFAEWNMT ViBOLYRPIJDROSTK KX 
Key----- BUS TI|IBUSIBUSINE|BUSIN 
Plain---T H I DAQTILLE Th. 
Cipher--D GD XIGUFIDJ UPS YiI. 

Cryptogram 

BOLYR PI DRO SKKKI FYXSXK DFIUPS YIYODP 
YFXUR APAEN MJUSTVB OLYRP SDROTI KKODGD 
XGUFD JSJUPSY ITXKKKX 


Sette LE | Pr xa rote etrtopet ett otey ey @ rs] EauaLaea 7 


SPStrtrpw trate ore tao ey rte a etry oy 


rstatorPrarstrtyiwrat etal rier erar ere trop eta 
A RACAEARs I aL ol Pray ster Twi ay err rote 


—_ | Y| DI 
SOUL UCLEOEEUDGDGGG 


Figure 14-12 f). Plaintezt letter as interrupter (U). 


—GONFIDENTIAL— 


14-12 


—GONFIDENFIAL— 


(1) In this example, the plaintext letter R 
was selected as the interrupter letter. Each time 
Rp appears, the key is changed following its encipher- 
ment, then the key reverts to its initial starting 
point. As a consequence of using a high-frequency 
letter, repetitions will occur quite often. This is 
true because a high-frequency letter will be a part 
of many common words, because it will be followed 
quite often by the same letter, and also because 
the word in which it appears may be followed by 
words that are frequently repeated. Thus each time 
the word ARTILLERY appears in the plaintext, 
the cipher equivalents of TILLERY must be the 
same because the key sequence reverts to its initial 
position following the encipherment of the R. 
If a low-frequency letter was selected as a plaintext 
interrupter, then each cycle of key usage would be 
greatly extended, resulting in an approximation of 
periodic substitution with the probability of numerous 
repetitions. 

(2) Although the length of the intervals between 
repetitions in any of the foregoing cases would be 
irregular, thus suppressing periodicity, the length 


Key-------B 


of each interval is normally sufficient to permit 
solution by two general methods. First, if the cipher 
alphabets are known from the results of prior 
analysis, and the cryptogram to be deciphered 
merely represents a key change, solution would be 
possible through the probable-word method. Second, 
repetitions found in the text would be examined in 
the light of their presence being due to a stereotype 
word. A probable word, then selected, would be 
applied in successive juxtaposition to the cipher- 
text. Using the known sequences, a key letter for 
each letter of the probable word would be derived. 
The process would be continued until such time as an 
intelligible key sequence was found or the probable 
word disproved. In the latter case, a different 
probable word would be assumed and the same 
process repeated. 

c. In the example above, a plaintext letter served 
as the interrupter letter. But suppose the corre- 
spondents had agreed upon a ciphertext letter instead. 
In this case the same message, using the same key 
and cipher sequences, would now appear as shown 
in figure 14-13. 


USINESSMACHINES BUSINES SM 
Plain----- AMMUNITIONFORFIRSTARTILLE 
Cipher----B OLYRPJDROIJKXTPFYXSXBPUU® 
Key~------ BUSINESSMACHIN(BUSINESSMACH[BU 
Plain---~- RYWILLBELOADEDIAFTERAMMUNITIIO 
Cipher----H RNMYTTXHPCRFQIBEJFIELLBONQO®@ 
Key-------B US INES S|MACHIBUSINE 
Plain----- NFORTHIR|IDARTIILLERY 
Cipher----V ECXBODFIPAZQIONUFIC 

Cryptogram 
OLYR PI DRO FJKXTP FYKSX BPUUVUQ HRWMY 
TITXHP CRFQB ETFIE LLBON Q@OQVE CXBOD 
FPAZQ ONUFI CXXXxX 


= Interruptor letter 


Figure 14~13 (eh Cipher letter as interrupter (U). 


Note that in this example there are no significant 
repetitions. This is due only to the selection of Qe 
as the interrupter. Had another letter been chosen, 


repetitions might have been plentiful. For example, 
note the repetitions occurring in the message shown 
in figure 14-14 when Se is used as an interrupter. 


14-13 


Key------- BANDSBANDSBANDSBANDSBANIBANDSBANDSB 
Plain----- FROMFOURFIVETOFOURFIFTEIENAMBARRAGE 
Cipher----K TA KZWXIIDACBNZWXIIDKWGIOWNKTBITIDETG 


69) = Interruptor letter 


P ABC DE F GH I og K LM 


ERE agar Paes ae ee ea ee 


Cl 

Ce ae Pit c|elel Fi ci s{x{MiwiolP 
C3 

ch 

cs [ST TP v[ Ww] x] Z{ a] yj O} Rf Aldo 


arroteTerstrtvtwL eT ala p ote tat oretr eter LE z 
/D | R ata rtetrtepetetetetetetetrtotey] 


N oP Q@ RS T U VW kK ¥ @ 


PQ; s[PiVviw{[x{ziaiy|oik 


ee eee ase ee 


Figure 14-14 p. Repetitions as a result of interrupter letter encipherment (U). 


(1) This last example provides a clue which 
‘may be used as an entry. Note that in this case the 
key is short, thus the key sequence is repeated 
several times before being interrupted. This of itself 
provides the possibility of repeated segments between 
periods of interruption. In such cases as above, where 
cipher repeats appear closely, the intervening letters 
between repeats may be eliminated from considera- 
tion as interrupter letters. Thus Ac, Ce, Bc, and Ne 
may be eliminated from consideration. 

(2) Insofar as analysis is concerned, two possi- 
-bilities are presented: superimposition or direct 
attack. In the first case, if the interrupter can be 
identified, the message may be divided into segments, 
each representing a key sequence run, and stacked 
as shown previously, the columns so formed being 
monoalphabetic. One difference in respect to the use 
of probable words should be noted. In cases similar 
to this, the analyst works from the inside of the 
message. That is, he attempts to find a given word 
in the body of the message. This is a much more 
difficult task than attacking the beginning of a 
message. This of course applies only to the case of 
stacking one message upon itself. Should depth of 
30 to 40 messages of the same system and key be 
available, this system can be solved more readily by 
superimposition. In the second case, a direct attack 


14-14 


upon an individual message is possible, but unless it 
contains some inconsistency in its text it can be a 
very difficult problem. 


14-8. (Q) Solution by Superimposition 

a. As mentioned previously in the case of both 
numerically keyed and interrupter-letter encipher- 
ment, solution is best accomplished by superimposi- 
tion which requires a depth of messages known to be 
from the same system. The solution will be made 
easier if the analyst has some preknowledge concern- 
ing the possible contents of the’ message. Here the 
knowledge of common stereotyped beginnings is 
invaluable. The general techniques used in this 
approach are demonstrated in the following para- 
graphs. 

b. The first two or three groups constituting the 
beginning of the message are selected from messages 
produced by the same system, superimposed to form 
a column. A uniliteral frequency distribution is 
made of these columns. Normally only the first two 
or three columns are so treated, because it is assumed 
that beyond this point the use of an interrupter in 
some of the messages will destroy columnar mono- 
alphabeticity. This process is demonstrated in 
figure 14-15. 


l PQPFYINGCRFKEXC 19. WYURNCWNUHEYUAHHK 
2. IGXPICTRFIFKEXGFEFW 20. VDNEFAYZKQXCMFT 
3. SQ@EQXETETIRAXDKX 21. TQCPFYAEQDDTRNC 
he MGQ@DFPNZYMORTYT oo. 2ECLUYLRAGPIPOOD 
5S. TQPPXCFNETINQXP 23. KRWTSPUZEDMGING 
6. FMABMRHZKTCGDTS 2h. TQBZXAUSPBFRMDX 
7 KBYTDHCKHIMGIRZ 25. TQXCFOLYGDYTBYVF 
8. IUERBGKQDAPPZQA 26. IGXSNGMAYZOZFT® 
9: FEV PLEX LY TEOX OR 27. KBYPSYQEXSDYIRG 
10. TQCFTBRIUWQEZUY 28. GRCP OCU FOOT NTARA 
ll. TQOBZBZEFKFLZTIRA 29. FDDYSDYIRGCTILME 
12. PQALATKQDFPNZYM 30. DQRYHRHEZKTCGDITR 
13. DGSBIJIBMKBQATSB 3l. CHAPQGAZEMCOQDFP 
1k. TQMPONLQOGZQDFP 30, RDALDKIEUSLP WO DEK 
5. PER, PAE LAL LLE LAC 33. KSHGROIJNQZNHOGQA 
16. GHNHHMKTSNBXLR2Z 3h. SQOPFXRSCARLZBCW 
17. CHMFTIRAXDXDNNF 35. POMPOAQFMLZYWFP 
18. EG YLIROCUPRAE RUG T 
Column Number 1 
pe = 3 — — =~ __ — 
ABCDEFGHISTKLMNOPQRSTUVWKXYZ 
Column Number 2_ 
= = 
ABCDEFGHISJKLMNOPQRSTUVWKXYZ 
Column Number 3 
ABCDEFGHITKLMNOPORSTUVWXYZ 
TQP 2 Tex'3 TQ 9 
TQC 2 IGY 2 I6°5 
TQB 2 
TOM 2 
TQX 1 


Figure 14-15 q. Frequency distribution and polygraphs of superimposed columns (U). 


c. The distribution derived from the first three 
columns exhibits several interesting characteristics. 
Note that the first distribution shows a pattern 
similar to that expected for a monoalphabetic 
distribution, but that the second has two peaks 
which seem abnormally high. These two peaks 
probably represent two vowels. The third distribu- 
tion is somewhat flatter than the first. This may be . 
the result of a key change occurring in several of 
the messages included in the distribution at this 
point. Considering these possibilities, the repeated 


trigraphs and digraphs observed may be examined 
for possible stereotype words. 

(1) The repeated TQe digraph followed an 
equal number of times by Pc, Cc, De, and Me is 
characteristic of the digraph REp in typical mes- 
sage beginnings, such as REQUEST, REFER- 
ENCE, REFER, RECEIPT, RECOMMEND, etc., 
and provides a ready point for initial assumptions. 
The only problem is associating the correct word 
with the correct digraph. In some instances the 
frequency of individual patterns compared to the 


14-15 


—CONFIDENTIAL— 


expected frequency of digraphs and trigraphs may 
provide a clue. In others such as this, where similar 
frequencies are involved, final resolution is merely 
a matter of trial and error. With this in mind and 
accepting that TQc is REp, the following associations 
are arbitrarily made. 

P REC REP REQ REF 

C TQP TQC TRB TQM 

(2) Using the assumed equivalencies and as- 

suming that the plain component is a direct stand- 
ard alphabet, a matrix may now be set up as follows 
(fig. 14-16). 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


eee 
oe COHeenGe 
3 AACAACHAAWOHGERCCUAMONUEI 


Figure 14-16 (C). Initial placement of values (U). 


(3) The assumed values for the third alphabet 
1 CC TQPFYINGCREKEXC 


P REC 
2. C IGXPSFJCTREFKEXGEW 
P00 
3. C SQEQXKETETIRAXDX 
P SEN 
4, C MGQDFPNZYMORTYT 
P YOB 
5. C TQPPXCFNETINQXP 
P REC 
6. C FMABMRHZKTCGODTS 
P FIR T 
7 C KBYTDHCKHIMGIJIRZ 
P ATT 
8. C TUERBGKQDAPPZ@QA 
P CAN 
9. C ITGYIXGKPYZKQXQR 
P cOT 
10. CC TQCFTFBRIUWQEZUY 
P REP 
ll. C TQBZBZFKFZZTIRA 
P REQ 
12. C PQALATKQDFPNZYM 
P VER 
13. C DGSBIIBMKBQATSB 
P HOZ 
ke C TQAMPONLQOGZQDFP 
P REF 
15. C IGXBJIJGLNYZZELAG 
P COU 
16. C GHNHHMKTSNBXLR2Z 
P ENE 
17. C CHMFTIRAXDXDNNP 
P INF 
18. C IGYIRGCNHAEFUGI 
, P cot 


reveal two distinctive patterns that indicate the 


. type alphabet involved. Note that Re-- Me and 


CBe are in reverse order, and also that the valyes 
involved are reciprocal, that is Cp=Pe and Pp=Cc. 
As the two patterns are characteristic of a reversed 
standard alphabet, this configuration is inserted in 
all three cipher sequences (fig. 14-17). The assump- 
tion being that, as in most cases, the secondary 
sequences are derived from the successive juxta- 
position of two basic sequences. 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 


pao Ud CCG UE GER CERELROBGUGRELE 
eg oa GaGa 


03 [eal lof ala ia| ely a] ela} ele [ojel ala] |e lxlel vez] 


Figure 14-17 (C). Completion of assumed sequences (U). 


(4) Using this matrix, the first three columns 
of each message beginning are now deciphered as 
shown in figure 14-18. 


19. C WT RNCNMHEYUAHEHK 
P OBA 

20. C VDNEFAYZKQKCMFT 
P PRE 

al. C TQCPFYAEQDDTRNC 
P REP 

22. C 2GLIUYLRXKGFITOOD 
P LOG 

23. C KRWTSPUZEDMGING 
P ADV 

ah. C TQOBZXAUSPBFRMDX 
P REQ 

2. C TQXCFOLYGDITBVE 
P REU 

26. C IGXSNGMAYZOZFTQ 
P COU 

27. C KBYPSYQEXSODYIRG 
P ATT 

28. C GXCPCIJFOOITNIARA 
P EXP 

29. C FDDYSDYIRGCIILIME 
P FRO 

30. C DQRYHREZKICGDIR 
P HEA 

31. C CHAPQGAZEMGQDEP 
P INR 

32. C KDALKILMSLPWQDK 
P ARR 

33. C KSHGROIJNQZNHOQA 
P ACK 

BU. C SQPFXRJIJGARLZBCW 
P SEC 

35. CC TO@MPOAQFMLZYWFKFP 
P REF 


Figure 14-18 Co) . Insertion of plaintext values (U). 


14-16 


—CONFIDENTIAL— 


CONFIDENTIAL — 


(5) Several of the trigraphs so produced ean 
easily be expanded to full words. Among these are: 


REC RECOMMEND or RECEIVE 
FIR FIRST 

ATT ATTACK or ATTENTION 
CAN CANCEL 

REQ REQUEST or REQUIRE 

COU COUNTER 

ENE ENEMY. 

INF INFANTRY or INFORMATION 


Other trigraphs seem to be impossible combinations 
of letters. Among these are: 


YOB OBA 
COT LOJ 
HOZ INR 
P ABcCDEFGHI J 
or irl sa ol plo wit xia) t a 
| | | [| 


Using this sequence, the trigraphs assumed to be 
good may now be expanded to: 


1.C TQPF 7.0 KBYT 
P RECO P ATTA 
2.C I@XP 8C IUER 
P  COUE P CANC 
3.C SQEQ. 1.C GHNH 
P SEND P ENEN 
6. C FMAB 17.C CHMF 
P FIRS P INFO 


(7) Each of the tetragraphs produced by this 
sequence conforms to the words assumed, with the 
exception of number 2. But note again that the O 
appears as plaintext. Moreover the same sequence 
applied to the improbable trigraphs now produces 
the following: 

YOBQ HOZS LOJZ 
COTL OBAG INRE 


Thus a key change is indicated, and since O appears 
in all except INRE, which now appears to be two 
words (IN RE), it may be tentatively accepted as the 
interrupter letter. This being the case, the obvious 
step is to confirm this assumption by trying to 
decipher these groups that revert back to cipher 


6 FMABMR 
FIRSTA 
oR BY TODA 
ATTACK 

8 IUERBG 
CANCEL 

14. TQ@MPON 
REFERE 

Key KURTFR 


KZN Ope 


This may be explained by a period of interruption 
occurring somewhere in the first two positions of 
these messages. In respect to this, note that, with 
the exception of INR, the letter “O” is common to 
all. 

(6) To test the possibility of a key change 
being involved, a fourth cipher sequence for those 
seemingly good trigraphs can be constructed. The 
equivalencies thus established then can be tested 
against those which seem improbable. If the tetra- 
graphs produced seem illogical, a key change may 
be assumed. Thus the following is produced: 


KLMNOPQRS TUVWRX Y Z 


ee oe 


| | 
a|r|z)p|o|a|a 2) 
P| i H 


4 ! | i 


<i 


sequence 1 each time the Op appears. Doing this, we 
find that the questionable groups now produce: 


2 C IGXP 19. C WTRN 
CONF P ORDE 

* * 
4. C.M@QD 22.C ZGIU 
P YOUR P LOCA 

* * 
9 C IGYJ 31. C CHAP 
P COMM P INRE 


(8) The appearance of valid plaintext confirms 
the assumption of Op as the interrupter letter. The 
final solution is now quite simple. Knowing the 
sequence of the cipher and plain components, and 
having identified the interrupter letter, all that 
remains to reconstruct the system is to determine 
the number of alphabets involved and their respee- 
tive juxtapositions. This can be done by selecting one 
or more messages in which the probably word or 
words contain no O and juxtaposing the sequences 
to produce the known ciphertext. When the points 
of juxtaposition repeat, the full key length is repro- 
dueed. Thus, the matrix size is determined. For 
example: ; 


ZEKETCGDTS 
LU EBL Res 
Q O 
CE 
SSEN/KUR 


14-17 


whee The matrix may now be reconstructed as shown in 
agent Ais figure 14-19, and each message deciphered. 


P ABCDEFGHIJKLMNOPQRSTUVWXYZ 
cl 
c2 
C3 
ch 


cS 
cé 


CT 
c8 


eel loot eel 


Figure 14-19 (fp. Completion of matriz (U). 


14-18 ~GONFIDENTIAL— 


PART SIX (oy 
_ INTRODUCTORY CODE SYSTEMS 


CHAPTER 15 (¢) 
CODE SYSTEMS 


Section |. (¢) INTRODUCTION 


15-1. (q) Classification of Code Systems 


Codes differ from ciphers in two respects. First, a 
group of symbols (letters, numbers, or a mixture of 
both) is used to represent a letter, syllable, word, 
phrase, or sentence of plaintext. Second, as they are 
not generated by an enciphering process, they do 
not bear the same relationship to the structure of 
the underlying plaintext as does a cipher. As code 
systems are arbitrary in nature, each group having 
its own assigned value, they require the use of books, 
lists, charts, etc., to tabulate the codes and their 
. meanings. Codes may be classified by the number 
and type of documents used. 

a. Open codes are systems of disguised secret 
writing in which units of normal plaintext are used 
as the code equivalent for letters, numbers, words, 
etc., of the plaintext message. They can be, and 
often are, combined to form an intelligible text of 
an apparently innocent message. An example of 
such an open code message is the poem passed by 
BBC on 1 June 1944 warning the French under- 
ground that the invasion of France was to be 
launched in less than 2 weeks: 


LES SANGLOTS LONGS 
DES VIOLONS 
DE L’AUTOMNE 


Another example is the following message passed to 
Secretary of War Stimson at the Potsdam Confer- 
ence to advise him of the success of the explosion of 
the first atomic bomb at Alamogordo, New Mexico. 


DOCTOR HAS JUST RETURNED MOST EN- 


rt 


AND COULD HAVE HEARD HIS SCREAMS 
FROM HERE TO MY FARM. 


The BIG BROTHER referred to in the preceding 
message is the atomic bomb dropped on Hiroshima 
on 6 August 1945. 

b. Book codes are code systems in which the code 
groups are contained in bound documents, arranged 
in some systematic order. They may be classified as 
either one- or two-part codes. 

(1) A one-part code is a code in which the 
plaintext element and its corresponding code group 
are contained in one document, arranged in alpha- 
betic, numeric, or other systematic order. This is an 
example of a one-part code: 


165 GAS ALERT OFF 

166 GAS ALERT ON 

167 GAS ATTACK READY 

168 GAS HAS BEEN RELEASED 

169 GAS HAS BLOWN BACK 

170 GAS HAS CEASED TO BE RELEASED 
171 GAS WILL BE RELEASED AT (TIME) 


(2) A two-part code is a randomized code 
system consisting of an encoding book and a decoding 
book, or sections of either. In the encoding book or 
section, the plaintext equivalents are arranged in 
alphabetical or numerical order, the code groups 
being assigned at random. In the decoding section 
or book, the code groups are arranged in a systematic 
order, alphabetical or numerical, and are accompa- 
nied by their meanings as given in the encoding 
section. The significant difference between two-part 
codes and one-part codes is that, in the former, the 
sequential. relationship between code groups and 
plaintext does not exist. For example, compare the 
two-part code shown in figure 15-1 with the one-part 
code above. 


— GONFIDENTIAL— 15-1 


468-095 O- 72-15 


HALE O760 Few 


MF 61 Intersect ing ion s 
NG 62 Short ly 

H 63 Circular s 

I 64 U 


0765 Centimeter s 
66 Repulse ing s 


67 Your message (No.) 
68 Assembly point s 
69 Runner s 


O770 Air base 
71 River s 
72 Mask ing 
73 Built 

' 74 Gain ing 


ENCODING SECTION 


WEI P 2583 Intercept ing ion or s 
XIGL 2756 - station 

K AXP 1072 Intercepted 

ROTB 2043 Interdict ing ions 
WOGL 2631 Interdicted 

QOPY 1889 Interfere ing nce s (in) 
GAVQ 0620 Interfered (in) (with) 
XAXD 2722 Intermediate 

HIZR 0oO82h Intermittent iy 
BOGcC 0081 Interpreter s 

ZEIN 2883 Interrogate ing ion s 
LAVM 1220 Interrupt ing ion s 
MY EP 1479 Interrupted 

H AMF 0761 Intersect ing ion s 
ZUST 2967 Interval s (of) 


FIPI 0514 Key s 
CUFZ 0255 Ki 

K AK B 1059 Kill ing s 
FYVM 0595 Killed 

CI QM 0215 Kilocycle s 
HODU 0828 Kilometer s 
VYRU 2541 Kind s (of) 
GY KZ 0734 Kitchen s 
NOPA 1589 Knew 
QAGT 1806 Knot s 
QYXE 1947 Know ing s 
KY TF 1193 Knowledge (of) 
LY XI 1347 Known 
FIKD 0509 Ko 

MOKW 1434 Ku 


Boing eae ee 


HIGH 0815 Meteorological 
16 Allowance s (for) 
17 Demoralize ation ing s 
18 Presence (of) 
19 Altogether 


0820 USS 
21 Release ing s 
22 «Fi 
23 Well 


24 Intermittent ly 


0825 Strengthened 
26 Often 
2T Void 
28 Kilometer s 
Favorable y 


Figure 16-1 . Two-part code (U). 


15-2. ( Matrix Codes 


a. Matrix codes as a class represent a transition 
between cipher and code systems. They may range 
from simple syllabary squares correctly classed as 
ciphers to code charts which include a small vocabu- 
lary of words and phrases. Generally, matrix codes 
follow closely the cryptographic principles of multi- 
literal systems treated previously. They differ from 
cipher systems primarily in their construction. In 


cipher systems, excepting the monome-dinome and 
monome-dinome-trinome systems. the ratio between 


plain and cipher elements is nearly constant. Matrix 
codes, however, have no definite ratio. Substitution 
of values may involve constant-length code groups 


for variable-length plaintext units composed of a 
mixture of letters, syllables, words, phrases, or 
sentences. An example of a typical matrix code is 
shown in figure 15-2. 


15-8 -CONFIDENTIAL— 


38 39 3 44 -45 46 


: a a [a Po [oo 
eet ee eee fees 
: a at 8 z 
Ce 
ge Wicd Bali Bd Mo HO Ba 
GUN 
' os dl 
TION 
31 | Reor | REPORT |Request} os | sector | SEND | SOUTH 
: reper fm ae oe] | = 
SPELL PELE 
oe ee 
«(pst ts Pepa ee 


Sample Message: 


BEGIN , END 
REPORT SPELL NE W SPELL POSITION OF RiGT STOP 
3140 ©6322 2945 3339 3246 3044 3040 3139 3236 


Figure 16-2 . Matriz code (U). 


b. The cryptographic operation of the system is when to begin spell (8242) and when to end spell 


quite simple, following the same methods as given (3246) is a means of entry into the system. 
for multiliteral systems. For example, the plaintext e. A variant form of the matrix code illustrated 
message: in figure 15-3 is the so-called “upper and lower case’ 
REPORT NEW POSITION OF REGIMENT matrix code. Essentially it is similar to the normal 
} . matrix code, only so structured as to contain two 
is enciphered as: plaintext values in each cell. Thus the capacity of 
3140 3242 2945 3339 3246 3044 3040 3139 3238 the matrix is doubled and variant plaintext values 
‘ ‘ for the equivalent code group are introduced. The 
Note that each plaintext value is represented by the cae eee eet ~ 
ae fk wena cryptographic operation of this system is <imilar to 
row and column indicator which intersected at the : : i ; 
position of the desired plaintext value. Thus 3140 that of the foregoing with one exception. That is, 
equates to REPORT. Note also that words which in this system at least two groups which normally 
do not appear in the chart are spelled out, as in the have but one plain value are set aside to indicate 
case of NEW which is represented by two code whether the groups following are upper or lower 
groups, 2945=NE and W=3339. This characteristic, case. An example of this system and the method of 
in conjunction with specific groups which indicates its operation are shown in figure 15-3. 


—CONFIDENTIAL— 15-3 


~GONFIDENTIAL— 


ee CR a os 
COMMUNT - 
CATION 


DISPOSI- 
TION 


Sample message: 
BEGIN ATTACK AT 1245 HOURS AND CAPTURE BRIDGE 321. 


BEGIN ATTACK UPPER CASE AT 1 2 y 5 
132 Ids 375 094 $92 132 372 494 


AND LOWER CASE CAPTURE BRIDGE UPPER CASE 
IIS 185 134 133 375 


3 2 1 
252 132 8 =—g2 


Figure 16-3 Sh. Upper case, lower case, matriz code (U). 


Although a system of this type introduces variant 
values, i.e. the code group 252 may indicate either 
the number 3 or the word COMMAND, it does not 
provide a great deal more security than the normal 
matrix code. Its chief advantage lies in the inclusion 
of a long vocabulary. 

d. Syllabary codes are used either to supplement 
a book code by adding a means of expanding its 
vocabulary, or to provide a flexible means of secret 
communications. As in all matrix codes, it appears 


R E C O N N 


in the form of a matrix. However, the contents of 
the matrix are normally limited to letters, numbers, 
and syllables. Cryptographically, it is also similar 
to multiliteral systems, having row and column 
coordinates for the purpose of designating the plain- 
text element within the cells of the matrix. A sample 
of a syllabary square is shown in figure 15-4. 


1 2 3 4 5 6 7 8 3 0 


AND | AR ARE | AS AT ATE 
2 3 CA CE co com 
3 DE E 5 EA ED IN EU? 
ees ce cece 


3 8 HAS | HE 9 IN TG} Ion} IS Iv 


8 R fra | Re | RED | RES | RI RO iS} SE SH 
g st STO | T TE TED TER | TH THE THI | THR 


Figure 16-4 5. Syllabary square (U’). 


The system provides for all the letters of the alpha- 
bet, the cardinal numbers, and the more common 
polygraphs. Also, the placement of the plaintext 
elements are such that the finding of any value is 
easy for the cryptographer. In effect, the system 
above provides variant values by the inclusion of 
both letters and polygraphs, without variant row 
and column coordinates. For example, the 
reconnaissance could appear in ciphertext as: 


A tI Ss S AN CE or 


word 


81 85 25 74 6O 60 11 54 88 88 14 28 
RECO N N AIS S AN CE or 

88 29 60 60 11 59 88 14 28 

R ECO N N ATS S A N C E or 

81 86 29 60 60 11 59 S8& 11 GO 25 36 


RE CON N AMIS SAN CE ete. 
88 25 76 GO 11 69 88 14 25 86 
e. Code charts are similar to the syllabary square type contains those common words, phrases, oper- 
in that they are of like dimensions and operate on ating signals, and words that relate directly to the 
the same cryptographic principles. A significant establishment and maintenance of communications 
difference between the two is that the code chart between two points. Provision is made for the 
CORPEIUNS words and phrases is normally designed to cardinal numbers and occasionally the letters of the 
serve a specific function, while the syllabary square alphabet. Although security of interoperator commiu- 


has more general application. Further, the code chart, 
being limited in intent, normally contains less 
internal variants. An example of these facets of a 
code chart may be seen in one of its more common 
applications: an operator’s code. A code chart of this 


15-4 


nications may be important in these cases, the chief 
object is to be the provision of a concise and rapid 
means of communications. Figure 15-5 depicts a 
type of operator code. 


—_CONFIDEN HAL — 


Ett 


Seog 
Peet Te 
PPE TCE ere 
EEE EE bl 
EEE fl 
PEPE EEE eS 
PEE ERE Eel 
PT ffm feet fel 
CE 
—faetebemt ET faa 


Figure 15-5 @). Operator’s code (U). 


15-3. (25 Enciphered Codes 


Occasionally the code groups of coded messages 
undergo a further process of encipherment; the 
resulting cryptogram constitutes an enciphered code 
message. Enciphered code is used to enhance the 
security of a widely held code. It can be used as a 
means of securing messages encoded in common com- 
mercial and telegraphic codes, and it can be used 
when increased security is required for highly classi- 
fied communications normally passed in a Jess secure 
system. 

a. Both of the two general classes of cipher 
methods, transposition and substitution, can be used 
to encipher code. Encipherment by transposition is 
used less as it is subject to error and requires highly 
skilled personnel for its practical use. The bulkiness 
of code materials and elements makes transposition 
encipherment of codes unwieldy for practical military 
use. 

b. All of the methods of substitution from the 
simple monoalphabetic methods to the most complex 


polyalphabetic systems can be used for the encipher- 
ment of code groups. Substitution tables of various 
sorts are often used. Tables may be used to convert 
5-letter code groups to pronounceable groups of 5 
letters, to convert 5-letter code groups to 5-figure 
code groups, or simply to convert combinations of 
letters into other combinations. The most important 
method, however, is the arithmetical method which 
is favored because of its simplicity and relative speed 
of operation as compared to that of the alphabetical 
methods. 

c. Two basic arithmetic techniques are used. They 
are addition and subtraction. In both, an arbitrarily 
selected sequence of numbers, normally correspond- 
ing in length to the code group, is added to or 
subtracted from the code group using nonearrying 
methods. The resulting sum or quotient becomes the 
ciphertext for transmission. The recipient of the 
message has only to reverse the operation, using the 
same key to uncover the plain code groups. Both 
processes are shown in figure 15-6. 


—CONFIDENTIAL 15-5 


CONFIDENTIAL— 


Additive: Enciphering 


Message FORCES DEPLOYED ALONG RIVLP LINE 


Code 2337 =: 1233 0864 0771 £970 
Additive 270l 2701 2701 2701 2701 
Text Go38 3934 2565 2b7e LeTL 


Deciphering 


Text 4038 3934 2565 
Subtractive 2701 2701 e701 
Code 2337 = 1238 0864 
Message FORCES DEPLOYED ALONG 


Subtractive: Enciphering 


Message FORCES DEPLOYED ALONG 
Code 2337 1233 0864 
Subtractive 8709 9579. 8426 
Text 1638 «= 2764 2 


Deciphering 
Text 2723 4638 4962764 2448 3513 
Additive 0891 o709 Yy5T79 8426 7268 3964 


Code 2514 2337 1233 0662 0771 4970 


Message ENEMY FORCES DEPLOYED ALONG RIVER LINE 


Figure 15-6 if Arithmetic enciphered codes (U’). 


The additive or subtractive may be fixed or variable. 
Fixed additives and subtractives, i.e. a series of 
numbers, the same or repeating, used to encipher 
each code group, are particularly weak cryptograph- 
ically if the basic code system contains any inherent 
limitations in size or sequential arrangement. If, 


however, a variable additive or subtractive, i.e. 


nonrepeating groups, is used, a much more secure 
system may be provided. Variable additives or 
subtractives are normally obtained from special 
tables or lists which contain a series of heterogeneous 
elements, none of which is used more than once. 
Using this method, a high degree of security may be 
imparted to the enciphered message, even if the 
basic code book is possessed by the enemy. 


15-4. (C) Disadvantages and Advantages of 


~" Code Systems 

a. One great disadvantage of code systems is the 
sheer bulk of material required to provide a com- 
prehensive vocabulary and the attendant problems 
of distribution and operation. However, code sys- 
tems offer certain advantages which in some cases 
may outweigh the disadvantages. The advantages are: 

(1) Code systems offer a more securc means of 
communications than most other hand systems, 
particularly in the case of small two-part codes 
which are superseded rapidly. 

(2) Economy in transmission is made possible 
by the nature of code systems. That is, it is possible 
to express an entire word or thought and convey it 
by a single group, whereas in cipher systems the 
same word or thought requires a great deal more in 
the way of ciphertext to accomplish the same thing. 

(3) Code systems are particularly adaptable to 
languages which are based on idiographs as are 
Chinese and Japanese. In Chinese for example, to 
allow for the transmission of idiographs, the “Chinese 
telegraphic code’ was compiled. This code contains 
10,000 characters, each represented by one code 
group and arranged similar to a two-part code. 

b. In terms of military usage, code finds its 
greatest application both in brevity codes and in 
field codes. A brevity code has for its sole purpose 
the shortening of messages and is not necessarily a 
secret code. An example of this type code may be 
observed in the Q and Z signals common to tele- 
communications. A field code, on the other hand, is 
a secret code and is designed primarily for low- 
echelon units. Code systems which are often used for 
this purpose are the matrix codes given above and 
occasionally two-part codes with limited vocabu- 
laries. An example of this type code may be seen 
in the current US Army KAC-P operation codes. 


Section Il. (9) ANALYSIS OF CODES 


15-5. (Z) Introduction 

The analysis of any code beyond the most simple 
form is dependent upon the availability of a volume 
of messages derived from the same system. The 
volume of messages required for successful analysis 
is in direct proportion to the complexity of the 
system. The analysis of complex systems generally 
presupposes the use of data processing equipment to 
sort, collate, and list significant repeats and char- 
acteristics observed in the raw traffic in preparation 
for analysis. The use of this material enables the 
analyst to enter the system through some identifiable 
characteristic. Through a preliminary study of 


associated communications data (callsigns, fre- 
quencies, operator chatter, etc.), characteristics of 
the code system (indicators, syllabary spelling, 
special indicators, etc.), and collateral information 
concerning the units and their operations, the analyst 
may isolate specific messages and identify certain 
plaintext values, such as placenames, personnel, 
and stereotypes which may be used to break into 
the code’s values. In short the analysis of code 
systems involves the study of large volumes of 
material. For this reason, and since in military 
usage code systems find their greatest application as 
field codes, this section will treat only the analysis 
of matrix codes. 


15-6 | -GONFIDENTIAL — 


-CONFIDENTIAL— 


15-6. (&f Principles of Analysis 


a. Since the cryptographic principles underlying 
the operation of matrix codes are similar to those of 
multiliteral systems, the same general techniques 
are used with some slight modification to fit each 
situation. Additionally, the characteristics them- 
selves provide a basis for analysis of the matrix 
code. These characteristics are given below, and 
their significance in terms of analytic attack is 
noted. However, they are not listed in order of 
importance, as the applicability of each is determined 
by the system itself, which is subject to variation. 

b. The plaintext values in a code matrix are 
usually arranged in some systematic order, usually 
alphabetically, to ease the encoding process. However, 
this is not always the case, for some systems may 
have plaintext values inserted in the cells of the 
matrix in random order. The significance of the former 
case lies in the possibility of assuming additional 
plaintext: values and of placing questionable values. 
For example, in the matrix code shown in figure 
15-2, note that the sequence of plaintext values in 
the first row of cells is “A, ADVANCE, AMMO, 
AN, AND, ATTACK, B, BE, and C” respectively. 
If the values “AMMO and AND” had been previ- 
ously placed, one could obviously assume that the 
intervening cell would contain a plaintext value 
beginning with A and having either an M or N as its 
second letter. Of course where the plaintext values 
are inserted randomly, this technique is inappropriate. 

ce. The row and column coordinates are usually 
one or two digits each, forming groups of two, three, 
or four digits. The coordinates where numbers are 
used may be in numerical order, some systematic 
disarranged order, or randomly ordered. The same 
situation may apply in cases where letters are used. 
However, since the amount of letters available is 
greater than the amount of numbers possible, vari- 
ations are increased. Insofar as analysis is concerned, 
the significance of two points, their identity and the 
method of their order, lies in the possibility of their 
use as a means of entry into the system. Usually, in 
all forms of matrix codes, the coordinates are changed 
regularly to provide a degree of security to offset 
the limitation imposed by the usual small size of 
the matrix, where interior values are generally 
fixed. Thus, once the initial recovery of a matrix is 
accomplished in part or in whole, analysis thereafter 
is concerned with the recovery of the row and col- 
umn coordinates. If a systematic method of genera- 
tion and assignment is involved, it is possible that 
the analyst may be able to predict their use in 
advance. If this does occur, then cryptanalysis is 
replaced by cryptography. The patterned use of 
row and column indicators is also of significance in 


the initial analysis of a matrix system as it often 
permits the placement of possible values within the 
matrix and the prior location of all coordinates 
during the initial stage of analysis. 

d. Also of importance to the cryptanalyst Is the 
use of special code groups within a matrix to indi- 
cate: begin spell, end spell, read number, read letter, 
upper case, and lower case. Note that the variant 
values provided by matrix systems for special 
meanings are usually somewhat limited. Therefore 
their use introduces a limitation into the resultant 
code which provides a sure entry into the system. 
The initial break into most matrix code systems 
and book codes, where syllabary spelling is a part, 
is through the recovery of syllabary spelling or 
numbers. The principle of analysis is quite simple 
where spelling is the basis of attack. The analyst 
searches the intercepted traffic for one or more groups 
which are repeated quite frequently, assuming that 
these groups represent the special indicators. Tf 
these are found, the code groups lying between are 
extracted and studied as either possible spelled 
words or sequences of numbers. These in turn are 
searched for recognizable patterns and compared to 
a list of suspect words or numbers which. through 
the analysis of collateral information, have been 
determined to be words likely to appear in the under- 


-lying plaintext. From this comparison, possible 


plaintext values are assigned to the code groups. 
the values being used to assume additional words. 

e. The complete solution of a given system nor- 
mally involves the use of one or more of the tech- 
niques outlined above, and when several are used, 
analysis is usually approached on a simultaneous 
basis. That is, after the system is first identified and 
its messages are isolated, all techniques are em- 
ployed to reconstruct the original encoding matrix 
and derive the plaintext equivalencies of the code 
text. The methodology involved herein is discussed 
in other paragraphs. 


15-7. D Identification 

a. Identification of matrix codes rests on their 
similarity to multiliteral systems. That is, the code 
groups will appear almost exactly like the cipher 
groups produced by long multiliteral tables. Factors 
which might serve to distinguish the two are: the 
repeated appearance of a few groups equating to the 
special indicators mentioned previously, and perhaps 
a slight variation between observed and expected 
digraphic frequency distribution. However, these 
means of initial identification are extremely tenuous. 
Normally, identification comes through either a 
process of elimination (that is, a solution is first 
attempted as a multiliteral, then when failing, the 
system is assumed to be a matrix code) or from 


—CONFIDENTIAL— 15-7 


—GONFIDENFHAL— 


preknowledge of the system in use by the corre- 
spondents. 

b. Code groups, when they are three to five 
digits in length, are normally transmitted in their 
original length. Smaller groups of two or three 
digits may be combined in some instances for 
transmission. The study of these groups often permits 
the identification of the code system. For example, 
code groups produced by a matrix often show 
positional limitations in their structure, again 


Row coordinates 


similar to the limitations produced by multiliteral 
cipher systems. This may be seen in the groups below. 


1344 7844 6322 7800 2311 3388 7344 1366 
5855 8322 6800 4833 2388 4377 0366 3366 
3300 6399 1333 2388 6322 7333 9311 7344 
1866 2388 


A glance suffices to show that only a few combinations 
of dinomes are involved in each group. The limita- 
tions in the case are: 


08, 13, 23, 33, 48, 53, 63, 73, 83, 93 


Column coordinates 00, 01, 22, 33, 44, 55, 66, 77, 88, 99 


With such obvious values as coordinates, the analyst 
could assume with certainty that the system is 
based upon a 10 x 10 matrix. Moreover, the pro- 
gression of the numbers themselves is possibly 
indicative of the order of their assignment to the rows 
and columns. 

c. As a general rule, positional limitations will 
always be present in matrix codes, although not as 
apparent. Exceptions to this rule occur when the 
number of rows or columns match the number of 
different values used. For example, in the case of a 
10 x 10 matrix where single numbers are used, all 
possible combinations are exhausted, thus no limi- 
tation will exist. This may be observed in figure 15-7. 


1 2 3 48 5 6 7% 8 9 90 


Code groups possible 00 through 99 


Figure 16-7 (U). 10 2 10 matrix, single digit coordinates (U). 


If on the other hand the number of possible combina- 
tions exceeds the total number of cells, a definite 
limitation exists. This may be observed in figure 
15-8. 


09 19 29 39 49 59 69 79 59 59 


Possible code groups 0009 - 9099 


Groups used 100 


Figure 18-8 (U). 10 z 10 matriz, dinome coordinates (U). 


15-8. (2) Matrix Reconstruction 

a. Matrix reconstruction in the case of initial 
analysis involves the study of characteristics, if 
any, of both coordinate generation and assignment. 
and the sequence of the plaintext values inserted 
in the cells of the matrix. If some systematic method 
is involved and is recognizable early in the analytic 
attack, the whole process of cryptanalysis can be 
greatly simplified. 


15-8 CONFIDENTIAL— 


-CONFIDENTIAE— 


b. In the case of coordinates, the analyst first 
determines if a limitation exists in the code groups. 
If this occurs, he uses these limitations to determine 
the total size of the matrix and the dimensions in 
terms of numbers of rows and columns. Using this 
information, he constructs a skeleton matrix. If 
some pattern exists in the digits used as coordinate 
indicators, he may attempt to place them correctly 
prior to the analysis of the internal plaintext values. 
The correct sequence of. randomly generated co- 
ordinates cannot, of course, be determined without 
the prior recovery of the internal values. Where 
generation is involved, prior or concurrent place- 
ment is always possible. In those cases where the 
coordinates are rapidly superseded and where all or 
part of the internal values are known, this becomes 
doubly important. Some examples of systematic 
generation are: 


Numerical order 
20 21 22 23 24 25 26 27 28 29 
Constant additive (+9) 
86 95 O4 18 22 81 40 49 58 67 
Progressive additives (+1, 2, 3, 4, 5, 6, 7, 8, 9) 
10 11 18 16 20 25 31 388 46 56 


c. When analysis has progressed to the point where 
plaintext values are assumed for specific code groups, 
the order in which they are inscribed in the matrix 
should be carefully checked. Often, but not always, 
inscription of plaintext values follows a specific route. 
If this route can be identified, assumption of plain- 
text values is greatly simplified as identification 
of each given group can be limited to u restricted 
number of choices. This limitation is expecially 
important where a pattern in the order of row and 
column coordinates has been predetermined. In 
this case the placement of plaintext values is not 
subject to distortion by errors of location. 


Section Il. (g) ANALYSIS OF MATRIX CODES 


15-9. (4) Analysis of Code Charts 


a. The analysis of procedure tables or operator 
code charts is usually a rather simple task. This is 
due in part to the internal limitations of the code 
chart and also to the circumstances in which the 
code chart would be used. For example, the code 
charts, as shown in the preceding example, are 
generally limited on content, subject matter, and 
occasion of use, and usually refer to the operations 
of a communications system only. Given the know]l- 
edge of the circumstances surrounding the trans- 
mission of a particular message, the analyst can 
usually infer its contents. Hence, it is but a short 
step to the recovery of the plaintext value. 

6. An additional factor that usually aids in solving 
these systems is that charts of this type are in- 
frequently changed. Thus the analyst over a period 
of time is able to recover all interior plain values. 
Once this has been accomplished, further analysis 
of the system becomes a case of key recovery. 

c. The periods of key usage will vary from case 
to case usually depending upon the usage of the 
chart. In some cases, they can be changed daily; in 
others, weeks may elapse before they are changed. 
In either case, key recovery is based on applying a 
procedure in reverse to that used heretofore, i.e. 
the analyst will find himself determining the correct 
cipher elements for one or more known values. For 
example, if the analyst knew that the digraphs 
Ol 52 22 10 54 related to a message “QSY 5965,” 
he would have little difficulty in placing the row and 
column indicators in their respective correct posi- 


tions. Further recovery and development of the 
chart is merely a matter of time. 


15-10. (t) Analysis of Syllabary Squares 


a. Essentially, the only difference between the 
method and technique of solving for plaintext of 


’ codes produced by a syllabary code and the previ- 


ously covered multiliteral system lies in the volume 
of material required. For a given code sequence of 
assumed plaintext value, a larger number of plain- 
text elements may have to be considered. The code 
text for the word RECONNAISSANCE shown in 
paragraph 15-2 illustrates this point. Four possible 
forms of encoding were given. Assume then that 
the analyst knows that the sequence 81 35 29 60 60 
11 59 88 11 60 25 35 equates to that word. Even 
with this knowledge, he still has to determine the 
correct way in which the word is divided, ie. does 
8ic=Rp or does it equal REp. In cases such as 
these, the analyst must modify his interpretation of 
frequency characteristics and idiomorphic patterns. 

b. As a general rule, solution of this system is 
quite difficult in those cases where a volume of 
messages produced by a given system is lacking or 
where the cryptographer has made full use of the 
variants available within the svstem. Fortunately, 
cryptographers often develop patterns of usage which 
are beneficial to the cryptanalyst. On occasion some 
will tend to reuse certain code values consistently, 
thus producing an easily identifiable word pattern. 
Moreover, this consistent use of one code value 
for one letter or polygraph establishes that one-to- 


—CONFIDENTHIAL— 15-9 


—CONFIDENTIAL— 


one relationship which quickly leads to the deter- 
mination of a plaintext value. 

ce. Another method in which it is possible to 
establish plaintext values for a number of variants 
is the analysis of a number of messages which have 
repeated elements, words, or stereotyped phrases. 
The significance of this can be observed in the cod- 
ings given for RECONNAISSANCE above. The 
similarity in the structure of the cipher sequences, 
representing different possibilities of encoding, would 
lead the analyst to valid assumptions concerning 
the structure of the underlying word. For example, 
consider the code group repeated in figure 15-9. 


(1) 81 35 25 74 60 60 11 S5¢ 88 88 14 28 


(2) 83 29 60 60 11 59 88 i4 28 


(3) 61 35 29 60 60 11 S59 88 11 60 25 36 
(4) 83 25 76 60 11 59 88 14 25 38 


Figure 16-9 gq). Idiomorphism in code sequences (U). 


(1) Examination of the first three code se- 
quences reveals the repeated dinome 60 preceded 
by four, three, and two dinomes respectively. Since 
60 is repeated, it is probably a single letter rather 
than a digraph or trigraph. If in the first code 


sequence the groups 8/ 35 25 74 represent 4 letters 
preceding the repeated letters indicated by 60, then 
the groups 83 29 of the second sequence must repre- 
sent the same letters as digraphs. Further, since the 
first and third sequences start with the same two 
dinomes, 81 and 35, but differ in that the groups 
25 74 of the first is replaced by 29 in the third, then 
83 of the fourth equals a combination of the values 
for 81 and 38, and 29 for 25 and 74. This can be 
shown as: 

81 385 85 74 

83 29 


60 60 
60 60 


Following the same logic, the following equivalencies 
are discovered: 


81+35=83 
25+74=29 
74+60=76 
64+88=59 
11+60=14 
25 +36 =28 


(2) With equivalencies established, it becomes 
possible to break the code sequence into uniliteral 
terms, thus forming the basis for drawing up word 
patterns. For example, the code sequences above 
could be reduced to the following code digraphs and 
one-word patterns established as shown: 


ABCDDEFGGEDBA 
81 85 25 74 60 60 11 54 88 88 11 60 25 35 


RECONNATISS ANCE 


d. Another method of entry into a syllabary 
square which does not require the depth of text 
that the above implies is the study and classification 
of repetition characters. This classification is based 
upon a general knowledge of the behavior of general 
classes of plaintext elements. For example, code 
units representing digits may appear in clusters 
representing time, map coordinates, etc. Further, 
particular digits in certain usages have positional 
limitations. The first digit of the 24-hour time sys- 
tem, for example, is limited to 0, 1, or 2; the second 
digit will use all numbers 1 through 0, the third 
from 0 to 5, and the last 1 through 0. Further, the 
0, one of the three numbers appearing in the first 
position, may also appear double in the last two 
positions with any noteworthy frequency. 

e. In either case, once sufficient equivalencies can 
be established, it becomes possible to reduce the 
greater part of the text to uniliteral terms and solve 
accordingly. The way is also opened for the recovery 
of the matrix. If the analyst has either a wholly—or 
a partially-recovered matrix available, the solution 
is thereby greatly simplified, as values can be 
assumed with a great degree of certainty. 


15-10 


f. An important point in respect to reducing a 
matrix code to uniliteral terms is that this is possible 
only under the circumstances where the encoding 
process proceeds along a nearly one-for-one basis. 
That is, a given code group equates to a given letter 
more often than it equates to a polygraph. Such a 
situation most often occurs in syllabary squares or in 
matrices which made them susceptible to this par- 
ticular method of attack. 


15-11. () Analysis of Matrix Codes 


a. The analysis of matrix codes follows the same 
general approach as that used for syllabary squares. 
That is, the code groups are studied to determine 
their inherent positional limitations. From their 
limitations the dimensions of the matrix are ussumed 
and, using the row and column values, a reconstruc- 
tion matrix is set up. Where possible, the initial entry 
into the system is made through sequences of 
syllabary spelling. Then, equivalencies for the code 
groups are established and the plaintext values are 
inserted into the body of the matrix. Once segments 
of spelling can be identified and the plaintext deter- 
mined, it then becomes possible to attack the 


—GONFIDENTIAL—— 


—CONFIDENTIAL— 


remaining code groups on the basis of possible plain- 
text values which can be associated with the spelled 
sequences. 

6. Note that this proposition depends entirely on 
the use of syllabary spelling in the code under 
analysis and the ability of the analyst to identify 
these sequences. Normally, identification is predi- 
cated on the basis of isolating repeated sequences in 
the code text of a number of messages. For this 
purpose an index listing prepared by data processing 
facilities may be used. An index listing is nothing 
more than a systematic listing of the groups that 
appear in a series of messages believed to have been 
produced by the same code system. There is no fixed 
type of index, its specific form being determined by 
the structure of the code system under analysis and 
the requirements of the analyst. Two common types 
are: an index of repeated groups, and an index of 
repeated sequences. 

(1) An index of repeated groups is made up of 
a listing of all repeated groups appearing in a number 
of messages. Additionally, the repeated groups are 
keyed to a specific message and location within that 
message. This type of listing is convenient to use 
where great numbers of codes are processed ancl 
where a complete listing of all the groups would be 
too bulky. It is also useful for the initial identification 
of the special indicators discussed previously. 

(2) The second general type is an index of 
repeated sequences. This can be based on the previous 
type index where specific groups have been isolated 
as spelling indicators or, if such are not used in a 
particular code system, simply a list of repeated 
sequences. This particular index form is especially 
suitable for the location and subsequent analysis of 


syllabary spelling sequences that occur in the body 
of a code as differentiated from stereotyped begin- 
nings or endings. 

c. In the case where no indication is given that a 
sequence represents a spelled word or phrase, the 
possibility always exists that it might represent a 
sequence of words rather than letters. In such cases, 
differentiation can sometimes be made on _ the 
frequency and position of the repeated groups. For 
example, if a repeated sequence of code groups 
appeared consistently at the beginning or ending of 
nu message, one could assume that it represented a 
stereotype address and, in this case, might represent 
words. On the other hand, if a given sequence 
appeared in different positions in several messages, 
one might assume that it represented a commonly 
used spelled word. In either case, note that identifi- 
cation of this sort is merely an assumption which 
has to be either proved or disproved in subsequent 
analysis. 

d. Assuming that a number of given sequences 
have been isolated as spell-sequences, the problem 
then is to determine what words are actually being 
spelled. The general approach is to attempt to fit 
the sequence to a stereotype common to the com- 
munications under study. These stereotypes may be 
military terms, titles, ranks, geographic place names, 
etc. In actual practice, the analyst’s familiarity with 
the communications system, the correspondents, and 
the area of operations is an invaluable aid. The 
actual recovery of plaintext equivalencies for code 
groups can make use of idiomophic patterns of the 
words. Note that these patterns may represent single 
letters as well as polygraphs, though usually digraphs 
are not common. 


15-11 


GONFIDENTIAL— 


APPENDIX A 2) 
FREQUENCY DISTRIBUTIONS OF ENGLISH 
DIGRAPHS 


Frequency distributions of English digraphs appearing in 50,000 letters of governmental 
plaintext telegrams, reduced to 5,000 digraphs. 


Table A—1 . Frequency distribution digraphs (U). 


__ BLANKS 


‘ale [c[ble) GOCIE GRC OOO RBUCIITEE 
fs fe [ular] s [ale [afi]s [a |anlval oe afi] [eaferfer[re| [3] [ra] [ols 
Pf tate] fede] fet fT fedets [a 


Puffa [fools fy] [att stoia] [5] 02 
|H [20] + | ileal a aia lel lal a 1| hn 
ae ele ey ae eee 


BOARDER 
lait | ttt te es fe fa | 
[R || ieee eee Sy ea meee 

|S [241 3 | DE HOODOO 
cle Slee eee eile aia 
Uls|sfataiujrfel ts] | [olstaly] | fate] fot | | | iiss 
vie} fo fs] fT pe ee ls 
whet [| feat fete Tet Patel Tee fe fee 
Kla] fatefats] [fat | tt fete tay deity TT zal 
LYielaiejejoiulrii[a] | [2ie/elols] fe iais[e] [1 Ei 
Z[s| | | 


aiSele aes 
rorat | [are oie [aos] oa io] 77723 vl « bo 
BLANKS Pals felelslelelelelvisieatereis sia sel xe 


CONFIDENTIAL 


Table A—2 (fe The 428 digraphs of Table A—1, arranged according to their absolute frequencies, 
accompanied by the logarithms of their assigned probabilities (U). 


10 L224 F [Lig {L224 
(QF) (F) i(F) 


21.08.58 
2/1.08 1.58 
12/1.08|.58 
12)1.08).58 
12}1.08 1.58 
12}1.08 1.58 
12;1.08).58 
11/1.04|.56 
11}1.04|.56 
11}1.041.56 
11/1.04|.56 
11:1.04).56 
11)1.04).56 
11)1.04).56 
1111.041.56 
10}1.001.55 
10} 1.00}.55 
10) 1.00).55 
10} 1.00.55 
10} 1.00}.55 
10} 1.00}.55 
0.951.53 
0.95.53 
0.95.53 
0.951.53 
0.95|.53 
0.95|.53 
0.951.53 
0.951.53 
0.951.53 
0.90).51 
0.90).51 
0.90.51 
0.90/.51 
0.90{.51 
0.90).51 
0.90}.51 
0.90;.51 


ee rg aa as gear erg array 
amt pret Pmt rend pemet pemet fermad pment fered feo Sree 
te et kt et ee 
oe eT Se ee ee ee 


~~] ~1 ~) © 00 0 CO 00 WH 0H OO WH OO © 10 19 10 10 10 10 10 OO 


! The 18 digraphs above this line compose 25% of the total. 
2 The 53 digraphs above this line compose 50% of the total. 
3 The 122 digraphs above this line compose 75% of the total. 


CONFIDENFIAL—. 


Table A—2 (WS. The 428 digraphs of Table A—1, arranged according to their absolute frequencies, 
accompanied by the logarithms of their assigned probabilities (U) — Continued 


Filio |Lo24 10 | L224 10 | £224 FiLig | L224 
(F) |(2F) se (2F) ge (2F) (F) |(2F) 

EH .... 7/0.85).4 $10.70) .42 310.48) .3 210.30].25 
EW... 70.8514 ...  510.70}.42 SM 2a 3.48133 62 210.30}.25 
EX .... 7/0.85 a aM eee 590.70).42 aN ... 310.48).33 JU. 2'0.30).25 
GA... 7/0.85}.48 SR .... 510.70}.42 LB .... 310.48].33 KI . 210.30}.25 
IP .... 710.851.48 TL .... 510.70].42 LC 310.48} .33 LM 210.301.25 
NU... 71/0.85/.48 TU .... 510.70).42 LF 3/0.48}.33 LR. 210.30}.25 
OA ... .7/0.851.48 UA... 510.70).42 LP 310.48) .33 LU 210.30)}.25 
OV... 710.85).48 UI .... 510.70).42 MC 310.48) .33 LV 210.301.25 
RG... 710.85|.48 UM ... 51.70).42 NP 310.48}.33 LW 210.30).25 
RN... 7/0.851.48 AF .... 410.60).38 NV 310.48).33 MR 210.30}.25 
TF .... 7/0.851.48 BA .... 410.60/.38 NW 310.48].33 MT 210.30|.25 
TN .... 7/0.851.48 BO .... 400.60).38 OE 310.48].33 MU 210.301.25 
XT .... 7/0.85}.48 CKe vee sb.s0 38 OH 310.48}.33 MY 2/0.30}.25 
AB .... 6/0.781.45 CR .... 410.60/.38 PH 3/0.48}.33 NB .. 210.301.25 
AG... 6]0.78).45 CU .... abe 38 PU 310.48}.33 NK 210.301.25 
BL .... 6)0.781.45 DB .... 410.60}.38 RH 310.48].33 OG 210.30 1.25 
GO... 6/0.78).45 DE es! se 38 SB 310.48/.33 OK 210.30 1.25 
ID .... 610.78).45 DN 4/0.60].38 SM 310.48/.33 | OY 210.301.25 
KE .... 610.781.45 DW Hie 38 TB 310.48/.33 PF .. 210.30 }.25 
LS 610.78 1.45 EB 410.60].38 UB 310.48}.33 RB .. 210.30 }.25 
MB 6}0.781.45 EG 40.60).38 UC 310.48}.33 SG .. 210.30 
OO 610.78 |.45 EY ‘bo 38 UD 310.48).33 SL .. 210.30 
PI... 6)0.78 |.45 GT 40.601.38 YI 310.48}.33 TP .. 210.30 
PS. 610.78).45 HS 410.60)|.38 YP 310.48|.33 UP . 210.30 
RF . 610.78 1.45 MS 410.60).38 AH 210.30).25 WN 210.30 

TC .. 610.78 ).45 NH 410.60/.38 AK 210.30].25 XA. 210.30 
TD ....° 6)0.78).45 NR 40.60.38 | AO 210.30|.25 >.< Caan 210.30). 
™ 6)0.78).45 - OB 40.60}.38 BI 2}0.30}.25 XI is 210.30}. 
UL .. 610.78 1.45 PM 410.60].38 BR 210.30}.25 XP .. 210.30 |. 
VA 610.78 ).45 RW 410.601.38 BU 210.30).25 YB .. 2'0.30). 
YA 6)0.78).45 SN .. 410.60}.38 DG 210.30).25 YL; 210.30 
YN 6}0.78 1.45 SW .. 410.60).38 DH 210.30}.25 YM . 210.301. 
CL... 510.70}.42 WH 410.60}.38 210.30}.25 ZE .. 2!0.30 |. 
DM 510.70}.42 Yc. 410.60}.38 FC 210.301.25 AE . 1/0.00}. 
DP .. 510.701.42 YD 410.60}.38 FL 2}0.301.25 AJ . 1j0.00 |. 
DU 510.70 1.42 YR 410.60}.38 GC 210.30|.25 BJ 1}0.001. 
FA . 510.70}.42 AA 310.48].33 GF 210.30).25 BM 110.00}. 
GI . 5}0.70}.42 AW 310.48|.33 GL 2/0.30).25 BS 1/0.00 |. 
GR 510.701.42 cc 310.48).33 GP 210.30).25 BT 110.00 |. 
HF .. 510.70|.42 DL 310.48).33 GU 2}0.30).25 CD 1;0.00 
NL. 5|0.701.42 DV 310.48}.33 HD 210.30}.25 CF 1:0.00 |. 
NM §}0.70|.42 EU 310.48}.33 HM 210.30)|.25 CM 1/0.00). 
NY 510.701.42 FS 310.48).33 IB 210.30}.25 CN 1}0.00 1). 
OI .. 5/0.70].42 FU 310.48}.33 IK 2}0.301.25 cs 1}0.00). 
RL. 5/0.70}.42 GN 310.48).33 IZ 210.30].25 CW 110.00 F 


A-s CONFIDENTIAL— 


Table A-—2 . The 428 digraphs of Table A—1, arranged according to their absolute frequencies, 
accompanied by the logarithms of their assigned probabilities (U) — Continued 


10 {£224 F le L224 FiILio | L224 
ts (2F) (2F) KF) | (2F) 
.13 . 


PD .... 
PN .... 


oS 
Ss 


SSSSSSSSSOSSSSSSSSS 
65686588888 8888S858 


foe 


rah Pah fend pant peeh peek pnd freed pune pd deme fh fem fens beh fed fined pred pane pond 
Op ct tt te ee 


SSSSSSSSSSSSOSSSSSSSS 
886866886886 55855888 
SSSSSSSSOSSSSSOSSSS 
888888885 S8SSS8888 


SeSd0000G000000099990% 
S©6565566566565655 


Table A—3 SZ). The 18 digraphs composing 25% of the digraphs in Table A—1, accompanied by the logarithms of 
their assigned probabilities, arranged alphabetically according to their initial letters (U) 


(1) AND ACCORDING TO THEIR FINAL (2) AND ACCORDING TO THEIR ABSOLUTE 
LETTERS — FREQUENCIES 


Lio [£224 F Lio |Lo24 Lio | £224 F {Lio 
F) |(2F) KF) |(2F) (F) | (2F) (F) 


468-095 O- 72-16 


“CONFIDENTIAL — 


Table A—4 (ot The 53 digraphs composing 50% of the digraphs of Table A—1, accompanied by the logarithms of 
their assigned probabilities, arranged alphabetically according to their initial letters (U) 


(1) AND ACCORDING TO THEIR FINAL (2) AND ACCORDING TO THEIR ABSOLUTE 
LETTERS FREQUENCIES 


F {Lyo jL224 


A-6 —GONFIDENHAL— 


CONFIDENTIAL — 


Table A-5 Ke The 122 digraphs composing 75% of the digraphs of Table A—1, accompanied by the . 
logarithms of their assigned probabilities, arranged alphabetically according to their 
initial letters (U) 


(1) AND ACCORDING TO THEIR FINAL LETTERS 


F [Lio | L224 F iLig L224 F i Lig | Lozq F Lio |Lo24 
(F) |(2F) | - (F) (2F) \(F) | (2F) (F) |(2F) 
AC .... — 14/1.15].61 ER .... 8711.94.94 |MA ... 3611.56.78 | RS ....  31{1.49'.75 
AD ... 27|1.431.73 ES .... 5411.73.86 JME ... 26)1.411.72 | RT .... 42)1.62).81 
AI .... 17}1.231.64 ET .... 371.57 .79 | 
Als. sccx* 32}1.511.76 EV .... 20/1.30.67 JNA ... 2611.41.72 [SA ....  24|1.381.71 
AM ... 14)1.15].61 Lge SUA ye NC .... 19)1.28).67 | SE .... 49]1.691.84 
AN... 64}1.81;.89 FI .... 3931.59.80 IND ... 5211.72;.85 {SH .... 26/1.41 22 
AR... 4411.64).82 FO.... 40/1.60.80 {NE .... 57/1.76:87 | SI .... 3411.53).77 
AS? e355 4111.611.80 NG ... 27)1.43).73 SO ....  1541.18!.62 
AT 824 4711.67}.83 GE.... 14.15.61 |NI .... 3011.48.75 | SS ....  19|1.281.67 
AU ... 13}1.111.59 GH ... 2011.30.67 |NO ... 1811.26.66 | ST .... 631/1.80/.88 
NS ....  2411.381.71 
BE .... 18}1.26).66 HA ... 20/1.30.67 |NF ... 82/1.91:93 |TA.... 2811.45.74 
HE .... 2011.30 .67 H | TE .... 7111.85).91 
CA .... 20}1.301.67 HI ....  33)1.52.77 JOF ....  2511.401.72 | TH .... 78/1.89/.92 
CE 32/1.51}.76 HO 2011.30.67 JOL.... 1941.28.67 | TI .... 45;)1.65).82 
CH 1411.15).61 HR 1711.23 .64 [OM 2511.40).72 |TO.... 5011.70].84 
CO .... 41}1.61)|.80 HT .... 2811.45.74 |ON ... 77)1.89192 |TR....  17/1.23).64 
CT ....  14/1.15}.61 OP ....  25/1.40172 | TS ....  19]1.281.67 
DA ... 32}1.51|.76 IC .... 2211.34.69 JOR ... 64/1.81:89 | TT ....  1911.28}.67 
DE .... 33)1.52}.77 TE .... 1311.11.59 JOS .... 1411.15.61 |1TW ...  3611.561.78 
DE aaa. 2711.431.73 IG .... 191.28 .67 JOT .... 1911.28]).67 | TY .... 41/1.61].80 
DO ... 16}1.20}.63 IL .... 2311.36.70 {OU ... 37/1.571.79 : 
DS 13}1.11].59 IN 751.88 .92 UN 21/1.321.68 
DT 15/1.18}.62 10 4111.61 .80 {PA 14/1.15}.61 | UR 3111.49.75 
IR 2711.43 .73, | PE 23/1.36}.70 
EA 35}1.541.78 Is 3511.54.78 jPO 17'1.23|.64 | VE 5711.761.87 
EC 32}1.511.76 IT 27\1.43 .73 {PR 18|1.26).66 
ED 60} 1.78}.88 IV 2511.40 .72 WE 2211.34.69 
EE 42)1.62).81 IX 15]1.18 .62 {QU . 1511.18).62 | WO 1911.281.67 
EF 18}1.26).66 
EI 27|1.43}.73 LA 2811.45 .74 |RA 39}1.59;.80 | YT . 15 1.18).62 
EL 2911.46|.74 LE 3711.57 .79 | RD 17|1.23].64 3,745 
EM 1411.15].61 ul 2011.30.67 |RE.. 9811.99].96 
EN 111]2.05].99 LL 2711.43.73 {RI . 30}1.48}.75 
EP 20}1.301.67 LO 13}1.11 .59 FRO 281.45 1.74 


CONFIDENTIAL __ 


Table A—5 (U). The 122 digraphs composing 75% of the digraphs of Table A—1, accompanied by the logarithms 
of their assigned probabilities, arranged alphabetically according to their initial letters (U) — 
Continued 


(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES 


Lig | L224 F |Lio {L224 F iLig | L224 
(F) |(2F) F) |(2F) (F) (QF) 


POO Ge Saco 
WON MATIN A ~~ 


As -CONFIDENTIAL— 


Table A—6 (ef. The 428 digraphs of Table A—1, arranged in alphabetic order by initial letters, then by 
absolute frequencies accompanied by the logarithms of their assigned probabilities (U) 


F iLio | £224 F Lio |L224 F 19 | Lo24 F |Lig | L224 
(F) | (2F) (F) |(@F) F) | (2F) (F) | (2F) 
AN... 89 ICT .... 14/1.151.6 ED .... 6011.78.88 |GH ... 20/1.30].67 
AT .... . 83 {CI .... 710.85 |.48 ES .. 5411.731.86 |GE 1441.151.61 
AR 82 {CL .. $10.70|.42 EE 42}1.62)}.81 IGA 710.8 5}.48 
AS . 80 iCK .. 4/0.60).38 ET 3711.57|.79 |GO 6'0.781.45 
AL .. 76 ICR... 4|0.60'!.38 EA 35/1.54|.78 | GI $10.70|.42 
AD 73 |CU 4/0.60].38 EC 32/1.51).76 |GR 50.70 .42 
Al .. 64 j;CC 3}0.481.33 EL 2911.46).74 |GT 4:0.60;.38 
AC .. 61 {CD 110.00}.13 EI 2711.431.73 1GN 3|0.48].33 
AM 61 jCF 1;0.001.13 EP 20}1.30).67 {GS 310.48).33 
AU 59 {CM 1)0.00].13 EV 20/1.301.67 | GC 210.30).25 
AP . 58 ICN... 1/0.00}.13 EF 18/1.26|.66 | GF 2}0.301.25 
AY 58 {CS . 1/0.001.13 EM 14/1.15}.61 GL 210.30}.25 
AV 48 | CW 1:0.00}.13 EO 12)1.08}.58 |GP 2}0.301.25 
AB . 45 |CY.. 110.00}.13 EQ 12}1.08).58 | GU 210.301.25 
AG 45 EH 710.851.48 |GD 1/0.00).13 
AF . .38 |DE 33}1.52|.77 EW 710.85|.48 |GG 110.00}.13 
AA 33 |DA 3211.51.76 EX 710.85|.48 | GJ 110.001.13 
AW 33 | DI 2711.43).73 EB 410.601.38 |GM 1{0.00}.13 
AH 25 | DO 16/1.20).63 EG 4/0.60}.38 | GW 1;0.00).13 
AK 25 |DT. 15)1.18).62 EY 410.60} .38 
AO 25 {DS . 13}1.11).59 EU 310.48! .33 
AE. 13 | DR 12}1.08).58 EJ 1/0.00].13 
AJ . 13 {DD 810.90}.51 EZ 110.00).13 | HI. 33}1.52).77 
DF 8/0.90).51 HT . 2811.45|.74 
BE . 66 |DM §}0.70}.42 FO . 40/1.601.80 |HA 20] 1.30!.67 
BY .. 48 | DP $10.70}.42 FI. 3911.59).80 |HE . 20) 1.30|.67 
BL . 45 | DU $10.70) .42 FF . 11/1.04.56 }HO . 2011 .30}.67 
BA . 38 |}DB. 4!0.60).38 FT . 1111.04.56. |} HR . 17/1.23}.64 
BO .. 38 |DC. 4/0.60;.38 FE . 10}1.00).55 jHU . 8}0.90/.51 
BI . 25 | DN 410.60/.38 FR. 910.95|.53 |HF .. 5\0.70].42 
BR. 25 | DW 410.60}.38 FA . 510.70!.42 {HS .. 410.60}.38 
BU. 25 |DL 310.48).33 FS . 3|0.48).33 [HC .. 3|0.48).33 
BJ .. 13 {DV 310.481.33 FU . 3|0.48}.33 [HN . 3}0.48).33 
BM . 13 |DG 2/0.30}.25 FC . 210.30}.25 }HD . 2'0.30}.25 
BS .. 13 |DH 210.30}.25 FL 2|0.30/.25 |HM . 210.301.25 
BT . 13 ;DQ 2|0.30}.25 FD 1/0.00).13 | HB. 10.00}.13 
DJ 110.00}.13 FG 1/0.00).13 | HL. 1:0.00].13 
co. 411.61)80 DY 1/0.00}.13 FM 1/0.00].13. | HP . 1:0.00].13 
CE. 514.76 FP . 1;0.00).13 | HQ 1/0.00/.13 
CA. .30}.67 | EN 111}2.05|.99 FW 1/0.00}.13 |} HW 1/0.00).13 
CH . 14)1.151.61 JER 87} 1.94).94 FY .. - 3{0.00).13 | HY 1,0.00}.13 


Table A—6 (U). The 428 digraphs of Table A~1, arranged in alphabetic order by initial letters, then by 
absolute frequencies, accompanied by the logarithms of their assigned probabilities (U) — 


Continued 
F iLio | 4224 F Lio | £224 F {Lio | L224 F [Lig |L224 
(F) |(2F) (F) | (2F) (F) | (2F) (F) |(2F) 

IN .... 75]1.88}.92 {LO ..:.  13)1.11/.59 ND... §2/1.72).85 jOV ... 710.85 /.48 
IO .... 4111.61}.80 |LY .... 1011.00.55 NI .... 30/1.48/.75 [OO ...  6/0.78].45 
IS .... 3541.54.78 {LD.... 910.95] .53 NG... 27|1.43].73 JOE .... 510.70}.42 
IR. .... 2711.43}.73 {LT .... 8/0.90).51 NA... 2611.41}.72 JOB .... 410.601.38 
IT .... 27|1.43].73 |LS .... 6(0.78|.45 NS .... 24]1.38].71 [OE ....  310.48).33 
IV .... 2511.40|.72 {LB ....  310.48}.33 NC . 1911.281.67. |OH 310.481.33 
IL .... 23/1.36).70 {LC .... 3/0.48} .33 NO 18}1.26}.66 {OG 2/0.30).25 
IC .... 22]1.34469 |LF ....  3/0.481.33 NEF . 910.95|.53 |OK 2/0.30}.25 
IG .... 1911.28|}.67 (LP .... 3}0.48] .33 NN 810.901.51 jOY . 2;0.30).25 
IX ....  15/1.18].62 }LM 2\0.30}.25 NU 710.85|.48 |OJ .. 1:0.00).13 
IE 13}1.11].59 |LR 210.30).25 NL 510.70/|.42 |OX . 1)}0.00!.13 
IF 10]1.00|.55 | LU 2/0.30}.25 NM 510.70|.42 
IM 910.95|.53 | LV 2/0.30}.25 NY 510.70|.42 |PE 23/1.36!.70 
IA 810.90].51 | LW 2/0.30}.25 NH 4/0.60).38 |PR 18|1.26).66 
IP 710.85}.48 ILG. 1/0.00}.13 NR 410.60}.38 |PO 17}1.23].64 
ID 610.781.45 |LH . 1/0.001.13 NP . 3/0.48|.33 |PA 14]1.15|.61 
IB. 210.30].25 |LN . 110.00!.13 NV 3/0.481.33 |PL 1311.11/.59 
IK 210.301.25 NW 310.481.33 {PP 11|1.041.56 
IZ 2/0.30}.25 {MA 36] 1.561.78 NB .. 2/0.30).25 {PT 810.90)|.51 

ME . 26] 1.411.72 NK 210.30].25 | PI 610.781.45 
JE. 210.30|.25 |MM . 13]1.11}.59 NJ. 1\0.001.13. |PS 610.78).45 
JO . 210.30125 |MO 10|1.001.55 NQ 110.00].13  |PM 4/0.60!.38 
JU. 210.30].25 {MI . 910.95].53 PH 3\0.48 1.33 
JA. 110.001.13 |MP . 810.90|.51 PU 310.48 |.33 

MB 610.78|.45 ON 77\1.89|.92 |PF 2/0.301.25 
KE 6|0.78|.45 |MS . 410.60|.38 OR 64/1.811.89 |PB 1'0.00).13 
KI 210.301.25 {MC - 3}0.48).33 OU 37/1.57).79 {PC 1)0.00'.13 
KA 1}0.00}.13  |MR 2)0.30}.25 OF 25}1.40|.72 {PD 1/0.001.13 
KC 110.001.13 {MT 2}0.30).25 OM 2511.40|.72 |PN 1'0.00'.13 
KL 110.00/.13  |MU 2\0.30}.25 OP 25|1.40|.72 {PV 110.001.13 
KN 110.00).13 |MY 210.30].25 OL 1911.28|.67 |PW 1/0.00;.13 
KS 110.00].13  }|MD 1/0.00}.13 OT 19/1.28].67 |PY 110.001.13 

MF 1\0.00}.13 OS 1411.151.61 
LE .. 37|1.57|.79 |MH 1/0.00].13 OD 12]1.08].58 
LA. 2811.45].74 oc 810.901.51 |QU 15/1.18|.62 
LL. 27(|1.43].73  |NT . 8211.91).93 Ow 810.901.51 {QM 1|0.00).13 
LI 20|1.30].67 |NE . 5711.76.87 OA 710.85|.48 |OQR 1/0.00}.13 


A-10 CONFIDENTIAL _ 


CONFIDENTIAL — 


Table A—6 (@). The 428 digraphs of Table A—1, arranged in alphabetic order by initial letters, then by 
absolute frequencies accompanied by the logarithms of their assigned probabilities (U) — 
Continued 


re DOW PAN 

ae SO9S999999 

DH OV ~3 OO CO DO@Owwh PAD~ 
— ee DW WWM AND 00 NO 
SSOSSSSSSSSSOS=» 

Ve et ee ee NN 


PRU 
— UN © em 00 
ta &\ 00 SSSQSwaADH Nw S2Onon DOOWPPeDIII IO 


ulanll oedema 
mM OWNno OOOOOwWwooeod 


A 
Bis 
SEASSSS BRBDRRRORA 


mr aAN~] 
OO°Oorr 


— KD 


mee ere tO BNW LOL 
OO Oo f OOwodnH7 SOOO wMWWWOOO~S 


— 
me NWANAAA~ II 


9990 S099900rrrer, 
OOun dd6 


NW 
— 
NN 


—CONFIDENTIAL — A-11 


-GONFIDENFIAL__. 


Table A-—7 (ef. The 428 digraphs of Table A—1, arranged in alphabetic order by final letters, then by 
absolute frequency, accompanied by the logarithms of their assigned probabilities (U) 


F ae L324 F [Lio | 4224 10 | £224 F Lio | Lo24 
(2F) (F) | (2F) (F) | (2F) (F) | (2F) 


RA ...  39)1.59}.8 3211.51).7 98 |1.99].96 wee 2)0.301.25 
MA ... 3ets0l78 ic wou 222 1346s TE wees TUGLB5S).91 Pe wee. 210,301.25 
EA .... 3511.54.78 [NC .... 1941.28.67 NE .... 5711.76.87 | CF .... 1/0.00;.13 
DA... 32/1.511.76 | AC ....  14)1.15).61 VE .... 57(|1.76|.87 | MF ... 1/0.001.13 
LA .... 28/1.451.74 [SC ....  1311.11).59 SE .... 4911.69.84 | UF .... 110.00}.13 
TA .... 2811.45).74 |RC ....  910.95).53 EE .... 42}1.62).81 | XF.... 1}0.00!.13 
NA ... 26(1.41|.72 |OC .... 8/0.90].51 LE ....  3741.57).79 
SA ....  24]1.38).71 | TC .... 6)0.78}.45 DE ....  33}1.52|.77 
CA .... 20)1.30]}.67 |DC .... 4/0.60).38 CE .... 32{1.511.76 | NG ...  27)1.43).73 
HA... 2041.30).67 {YC .... 410.60).38 ME ... 2641.41).72 | IG ....  1911.28).67 
PA .... 14)1.15161 [CC ....  3/0.48).33 PE ....  23/1.36).70 | UG 8/0.90].51 
WA 12/1.08}.58 | HC 310.48).33 WE ... 22/1.34|.69 | RG 710.85}.48 
IA . 810.90).51 | LC 310.48].33 HE .... 20/1.30/.67 | AG ... —6)0.78).45 
GA 710.85;48 {MC ...  3)0.48).33 BE .... 18)1.26).66 | EG .... — 4/0.60/.38 
OA 710.85|.48 | UC .... 310.48}.33 GE .... 14/1.151.61 | DG 2/0,.30}.25 
VA 610.78].45 | FC .... 2)0.30}.25 TE ....  13/1.11).59 | OG 2}0.301.25 
YA 610.78).45 | GC 2/0.30].25 UE ....  11/1.04/.56 | SG 2}0.30}.25 
FA 510.70}.42 | XC 2/0.30].25 FE 10]1.00).55 | FG 110.00}.13 
UA 510.70|.42 | KC 1}0.00}.13 YE 910.951.53 | GG 1/0.00).13 
BA . 4/0.60/.38 | PC 1}0.00}.13 KE 6/0.781.45 | LG 1;0.00}.13 
AA 310.48}.33 OE 3)0.48).33 | TG 1)0.00}.13 
XA 2|0.30}.25 JE 2}0.30).25 | YG 110.00;.13 
JA .. 1/0.00}.13 | ED 60] 1.78}.88 ZE 210.30}.25 
KA 110.00].13 | ND $2|1.72}.85 AE 1/0.00).13 
ZA . 110.00}.13 | AD ... 27/1.43}.73 XE .... 1/0.00}.13 

RD... 17/1.23).64 TH .... 78)1.89}.92 
AB . 6|0.78).45 {OD ...  12)1.08).58 d SH’....  26/1.41].72 
MB 610.78}.45 |} LD .... —910.95}.53 GH ...  20)1.30!.67 
DB. 410.60).38 | DD 8/0.90}.51 OF . 25|1.40)].72 | CH 14/1.15).61 
EB . 410.60).38 | ID 610.78].45 EF . 18}1.26).66 | EH 7/0.85|.48 
OB . 4/0.60/.38 | TD 6|0.78).45 SF . 12/1.08).58 | NH 4/0.60).38 
LB. 3/0.48}.33 | SD 5{0.70).42 FF . 11/1.04).56 | WH 410.60).38 
SB .. 3}0.48).33 | YD 4/0.60}.38 YF . 11)1.04}.56 | OH 3/0.48!.33 
TB . 310.48|.33 | UD 3/0.48].33 IF . 10{1.00|.55 | PH 3/0.48!.33 
UB . 3/0.48}.33 | HD 2}0.30}.25 NF . 910.95).53 | RH 3/0.48}.33 
IB .. 2/0.30).25 | CD 110.00;.13 DF ....  8/0.90/.51 | AH 2|0.301.25 
NB . 2)0.30).25 | FD 1,0.00}.13 TF ....  7}0.85).48 | DH 2/0.30|.25 
RB. 2/0.301.25 | GD 1/0.00}.13 RF ....  6/0.78).45 | LH 10.00}.13 
YB . 2/0.30].25 | MD 1,0.00}.13 HF 5{0.70}.42 | MH 1/0.00].13 
HB. 1/0.00).13 | PD .. 1/0.00).13 AF 4/0.60|.38 | XH 1\0.00}.13 
PB. 1)0.00}.13 | XD 1/0.00}.13 LF 3}0.48}.33 | YH 110.00}.13 


Ant? CONFIDENTIAL — 


Table A—7 (@§. The 428 digraphs of Table A—1, arranged in alphabetic order by final letters then by 
absolute frequency, accompanied by the logarithms of their assigned probabilities (U) — 


Continued 
() |QF) (F) | QF) () | QF) (F) | QF) 
45|1.651.82 711.43].7 64| 1.81|.8 aie. 1111.59 
eae 391159180 Ae Speen ay Se ol ce ape 12/1.081.58 
SI .... 341153177 loL .... 19/128167 | NN ... 8l090151 [PP .... 111,041.56 
HI _... 33(152177 |PL ....  13/1.11/.59 | RN 10.85/48 |SP . 10/1.00).55 
NI .... 30/1.48(75 IBL....  610.781.45 | TN. 10.85/48 | MP. 810.9015] 
RI |... 301148175 |uL.... 60.7845 | YN 610.78).45 | IP 7/0.85|.48 
DI .-.. 271143173 }cL |... 5l0.701.42 «| DN 410,601.38 | DP 510,701.42 
EI _... 2711.43.73 |NL.... 510,701.42 | SN 410,601.38 | LP 310,481.33 
LI 1... 201130067 | RL 510.701.42 | GN 3|0.481.33 | NP 310.4813 
Al 1711.23(64 |TL 510.70|.42 | HN 3/0.481.33 | YP 310,481.33 
WI 13/1.11/59 | DL 3/0.48/.33 | WN. 20.30/25 |GP | 210,301.25 
VI 12/1.08058 | FL 3/0.301.25 | CN .. ilo.00113 {TP . 2'0 301.25 
MI 910.95153 | GL 3/0.301.25 | KN 110,001.13 | UP . 2'0.301.25 
Cl 710.85/.48 | SL 21030125 | LN. 1!0.001.13 | XP . 2,0.301.25 
PI 610.7845 | YL 31030125 | PN. 110,001.13 |EP . 110.00) 13 
GI 5l0.70142 |HL 10.00/13 | XN ilo.00113 | HP | 10.00/13 
Ol 510.701.42 | KL 1/0.00|.13 

UI 510.70142 | WL 1)0.00].13 EQ 12|1.081.58 
YI 310.48) 33 TO .... 501.701.84 | DO 210.30).25 
BI 210.301.25 CO .... 41!161/.80 | HO 10.00/13 
KI 310.30125 JOM... 2511.40|.72 | 10 .... 41/1.61/80 [NO 110.001. 13 
XI 2030125 |AM ... 14|1.15161 | FO.... 40|160/80 |1TO .... 110.00113 

Zi 110.00/13 [EM ... 141.1561 | RO... 28/1.45/74 
MM... 1311.11.59 | HO ... 2011.30167 |ER 87/1.941.94 
IM .. 91095153 | WO 191128167 |OR 64|1.811.89 
ae il0.001.13 |RM .. 90.95/53 | NO ... 181126166 |AR ... 44/1.64/82 
BI 110.0013 17 0.78145 | PO .... 17/1.23164 |UR ... 3111.49/75 
DI 1/0.001.13 ‘| DM 510,701.42 | DO... 161120163 |IR 27|1.43).73 
EJ 110.00113 |NM 510.701.42 | SO. 1511.18]62 |PR 18/1.26166 
GI 110.0013 |UM 510.701.42 | LO. 13|1.11|.59 |HR 1711.23.64 
NJ 110.001.13 |PM . 40.60/38 | EO. 12|1.08]58 |TR 17/1.231.64 
Oo | 110.0113 {SM .. 310.4833 | MO... 10100155 |DR ... 12/1.08/.58 
RI. 10.00/13 |HM 0.30125 | Yo |... toltoolss |RR ... 111.04/56 
LM 1030125 | Go ... 61078145 |FR....  910.95153 
CK . 410.60|.38 | YM 710.3025 | 00 ... 610.78145 |GR ...  5j0.70142 
AK 2}0.30|.25 |BM il0.00113 | BO.... 40.6038 |sR....  5/0.70/42 
IK . 21030125 |CM il0.00113 | AO... 21030125 |CR..... 410.601 38 
NK 210.301.25 | FM ilo.001.13 | JO .... 21030125 |NR 410,601.38 
OK 310,301.25 |GM 0.00113. | UO... 1000/13 |YR ... 410.6038 
RK 11000113 {QM 0.00113 | VO ... 1lo00l13 |BR....  2/0.30/25 
SK . 110.001.13 xO |... 1000113 ILR....  2/0.30(25 
MR 31030135 
EN .... 11112.05|.99 OR 1l0.00/.73 
AL .... 32{1.511.76 ON... 77/1.89192 | OP .... 2511-40172 |WR 10.00/13 
EL |... 2911.46.74 JIN .... 751188192 | EP .... 20l1.30167 |XxR 10.00/13 


—GONFIDENTFIAL— A-13 


Table A—7 (ox The 428 digraphs of Table A—1, arranged in alphabetic order by final letters, then 


according to their absolute frequency, accompanied by the logarithms of their assigned 
probabilities (U) — Continued 


SOOO SSSOm ers 
mE NN WWAIION 


-COny OOOCOM 


RE RE RENN AUN 


aOoooddnoe 


ee KD 


08 
04 
90 
90 
8 
6 
3 
0) 
.0' 
5 
1 
1 
04 
9 
8 
7 
7 
7 
6 
4: 
.48 
4 
3 
3 


NN WWW OM ~1 
SSSOOSOOOS OEE == 
ot ee DOD WP P H ~) COD 


oOo 


A-14 CONFIDENTIAL 


CONFIDENTIAL 


Table A—8 (GY. The 18 digraphs composing 25% of the digraphs of Table A~1, accompanied by the logarithms of 
their assigned probabilities, arranged alphabetically by final letters (U) 


(1) AND ACCORDING TO THEIR INITIAL (2) AND ACCORDING TO THEIR ABSOLUTE 
LETTERS FREQUENCIES 


Lig L224 F {Lio {£224 Lio 
(F) | QF) (F) |QF) (F) 


r F 

60|1.78:.88 | IN .... ED .... 60 
52)1.72).85 | ON ... ieee. So 
5711.76 87 sda 70\. 98 
98'1.99'.96 oe 
49!1.691.84 ates 941, Revie SF 
7111.85'.91 mee 81}, Core! \ 38a 
$7'1.76|.87 wad 


7311.89.92 | dis, - 8 


6411.81 
111|2.05 


Table A~9 (€). The 53 digraphs composing 50% of the digraphs of Table A—1, accompanied by the logarithms of 
their assigned probabilities, arranged alphabetically by final letters (U) 


(1) AND ACCORDING TO THEIR INITIAL LETTERS 


F {Lig | L224 F Lio | £224 F [Lio | L224 F iLio |L22 
(F) |(2F) (F) | (QF) (F) | (2F) i(F) | (2F) 
DA... 32)1.51].76 NE ....  57{1.76).87 AN ... 64) 1.81.89 AS ....  41/1.61!.80 
EA .... 3511.54.78 RE .... 98/1.99).96 EN ....  111/2.05}.99 ES: iss oe 54: 1.731.86 
LA ....  28/1.45|.74 SE .... 49]1.69].84 IN ....  75/1.88).92 | IS ....  35/1.54/.78 
MA ... 36/1.56|.78 TE ....  71/1.851.91 ON... 77/1.89,92 | RS .... 31/1.491.75 
RA... 3911.591.80 .| VE ....  57)1.76}.87 H 
TA .... 28{1.45}.74 AT ....  47/1.67).83 
TH .... 78/1.89/.92 CO .... 4111.61|.80 ET ....  37)1.57|.79 
EC ....  32{1.51).76 FO ....  40/1.60|.80 | HT ....  2811.451.74 
FI 39|1.59).80 IO .... 41} 1.61}.80 NT 82) 1.91).93 
HI ....  33}1.52/.77 RO... 28) 1.45).74 RT .... 42!1.62).81 
ED .... 60/1.78).88 NI ....  30)1.48].75 TO .... 50} 1.70.84 ST ....  63)1.80].88 
ND...  52}1.72).85 RI .... = 30}1.48|.75 
SI ....  34)1.53).77 OU 371) 1.57)}.79 
TI 2... =4511.65).82 
CE ....  32)1.51).76 AR... 44) 1.64).82 TW 36) 1.56.78 
DE .... 33)1.52).77 ER vis. 871 1.941.94 
EE .... 42)1.62/.81 AL .... 32(1.51].76 OR... 64) 1.81].89 TY 41)1.61).80 
LE .... 3711.57}.79 EL .... 2911.461.74 UR 31} 1 75 2,495 


CONFIDENTIAL —— A-15 


GCONFIDENTFIAL_—_— 


Table A-9 (ok The 53 digraphs composing 50% of the digraphs of Table A~1, accompanied by the 
logarithms of their assigned probabilities, arranged alphabetically by final letters (U) — 
Continued 


(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES 


Lig Ly24 F Lig L224 
(F) (2F) (F) (2F) 


Table A—10 (QZ). The 122 digraphs composing 75% of the digraphs of Table A—1, accompanied by the 
logarithms of their assigned probabilities, arranged alphabetically by final letters (U) 


(1) AND ACCORDING TO THEIR INITIAL LETTERS 


(KF) |(2F) (F) |(2F) F) |(2F) (F) | (QF) 

20)1.30!.67 2/1.72).8 811.261.66 |SI ....  34/1.53/.77 

a ... 3241.511.76 RD ie ose hk Sali ae 72 |TI....  4511.65}.82 

EA .... 3511.54}.78 

HA ... 2011.30.67 |BE .... 1811.261.66 IG .... 19]1.28167 [AL ....  32/1.511.76 

LA .... 2811.45]1.74 |CE .... 3211.511.76 NG ... 27/1.43.73 [EL ....  29/1.461.74 

MA ... 36/1.561.78 |DE .... 33/1.521.77 IL ....  2341.36].70 

NA ... 2611.411.72 |EE....  4211.62/.81 CH ....  14/1.15].61 | LL .... — 2711.431.73 

PA .... 14)1.15/.61 LGE.... 1411.15).61 GH ... 20/1.30/).67 |OL .... — 19/1.28].67 
RA ... 3911.59.80 [HE .... 2011.30).67 SH .... 26)1.41|.72 
SA ....  24{1.38).71 JIE ....  13/1.111.59 TH .... 78|1.891.92 

TA .... 2811.45.74 | LE ....  3711.571.79 AM... 1411.151.61 

ME ... 26/1.41|.72 AL ....  17/1.23),64 |EM ... 9 14)1.15].61 

AC ....  14/1.15].61 | NE ....  57/1.76|.87 DI .... 2711.43.73 |OM ...  2511.401.72 
EC .... 32/1.51).76 | PE ....  23/1.36|.70 EI ....  27/1.431.73 

IC .... 22)1.341.69 | RE .... 98/1.991.96 FI .... 39/1.59180 | AN ...  64{1.81].89 

NC ....  19]1.281.67 |SE .... 49/1.69].84 HI .... 3311.52.77 | EN ....  11112.05|.99 

TE ....  71/1.85/.91 LI .... 2011.30.67 | IN ....  7511.88}.92 

AD ... 27/1.43.73 | VE.... 5711.76.87 NE .... 30/1.48175 |ON ... 7711.89.92 

ED .... 60/1.78.88 |WE ... 2211.341.69 RI .... 3011.48175 |UN ...  2111.321.68 


A-16 -GONFIDENTIAL— 


—GONFIDENTIAE- 


Table A—10 0. The 122 digraphs composing 75% of the digraphs of Table A—1, accompanied by the 
logarithms of their assigned probabilities, arranged alphabetically by final letters (U) — 
Continued 


(1) AND ACCORDING TO THEIR INITIAL LETTERS— Continued 


(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES 


(F) GF) (F) | (2F) (F) jQF) (F) | CF) 
39)1.59).80 we. 98/1.991.96 TH .... 78/1.891.9 woe 5}1.40].72 
MA --. 36/1.561.78 TE eee. 7141.85).91 SH ....  26/1.41 35 AM a altistei 
EA .... 3511.54.78 |NE ....  57)1.76).87 GH ... 20/1.30)67 | EM ... 14}1.151.61 
DA ... 32/1.51176 |VE ....  57)1.76|.87 CH ....  14/1.15|61 
LA .... 2811.45.74 |SE .... 49/1.691.84 EN ....  111/2.05|.99 
TA .... 2811.45.74 |EE ....  42/1.62).81 ON ... 7711.89).92 
NA... 26/1.41,72 {LE ....  37/1.57}.79 TI .... 45/1.65182 | IN .... 7511.88)}.92 
SA ....  24/1.38).71 |DE ....  3341.52).77 FE 1... 39;)1.591,80 | AN... 64/1.81|.89 
CA .... 20/1.30.67 |CE ....  32)1.511.76 SI ....  34/1.53,.77 | UN ... 2111.32.68 
HA ... 2011.30,67 |]ME ... 26)1.41}.72 HI ....  33/1.521.77 
PA .... 14)1.15).61 |PE ....  2311.36).70 NI. .... 30/1.48,.75 | TO .... 5011.70}.84 
WE ... 22)1.341.69 RI .... 30)1.481.75 | CO.... 41/1.611.80 
EC .... 32)1.51.76 |HE .... 20/1.30|.67 DE ....  27/1.43173 [IO ....  4141.611.80 
IC .... 22/1.34.69 {BE ....  18|1.26|.66 EI ....  27)1.43.73 | FO.... 40/1.60).80 
NC .... 19/1.28167 |GE ....  14]1.151.61 LI .... 20/1.30}67 | RO ... 28)1.451.74 
AC .... 14/1.15.61 [TE ....  13/1.111.59 Al ....  17)1.23)64 | HO ... 20)1.30}.67 
wo... 19}1.28].67 
OF ....  25/1.40}.72 AL ....  32)1.51).76 | NO... 1811.261.66 
ED .... 60j1.78188 {EF ....  18/1.26).66 EL .... 2911.46.74 | PO.... 17}1.23).64 
ND... 52/1.72185 LL .... 27/1.43.73 | DO ... 16)1.201.63 
AD... 27/1.43173 ING ...  27/1.43).73 IL .... 23/1.36170 | SO .... 1511.18.62 
17}1.23164 |IG ....  1911.28).67 OL .... 19)1.28)67 ;} LO.... 13]1.11).59 


A-17 


Table A-10 & The 122 digraphs composing 75% of the digraphs of Table A—1, accompanied by the 


logarithms of their assigned probabilities, arranged alphabetically by final letters (U) — 
Continued 


(2) AND ACCORDING TO THEIR ABSOLUTE FREQUENCIES— Continued 


F Lig {L224 Lio | L224 
F) |QF) (F) | QF) 


OP .... 25{1.40].72 


87}1.94 

6411.81). 

44}1.64 
11.49). 
7\1.43), 
8}1.26}. 
7/1.23 
741.23). 


be et pet DK QD 


A-18 —-GONFIDENTFIAL_— 


APPENDIX B (Z) 
FREQUENCY DISTRIBUTIONS OF ENGLISH 
TRIGRAPHS 


Frequency distributions of English trigraphs appearing in 50,000 letters of governmental 
plaintext telegrams. . 


~GONFIDENTIAL- | 4 


B~2 


CONFIDENTIAL- 


Table B—1 ). The 56 trigraphs appearing 100 or more times, arranged according to their absolute 
frequencies, accompanied by the logarithms of their assigned probabilities (U) 


Table B—2 (PI. The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by initial 
letters, then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) 


CONFIDENTIAL — 


Table B—3 (25. The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by central 
letters, then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) 


COKMRNNNW 
BAwnoou- 


Am VN 


NN NS YN NOY PNYN NO” VNVNYNNNNVE 


wn NW Ww 
be 


Table B—4 (S. The 56 trigraphs appearing 100 or more times, arranged in alphabetic order by final letters, 
then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) 


— bw 
On 


OOrNN ~~ 


ou 
NW GD®oO NADNOA 


NN NNW YVYNNHNN NN 


wos 


B-3 


468-095 O- 72-17 


~GONFIDENTIAL- 


APPENDIX C (J 
FREQUENCY DISTRIBUTION OF ENGLISH 
TETRAGRAPHS 


Frequency distributions of English tetragraphs appearing in 50,000 letters of governmental 
plaintext telegrams. 


CONFIDENTIAL— 


Table C—1 lind The 54 tetragraphs appearing 50 or more times, arranged by absolute frequencies, 
accompanied by the logarithms of assigned probabilities (U) 


153:2.18].93 
153 2.18193 
152'2.18).93 


133318193 


2161.92 
2.15.92 
2.131.91 
2.13).91 
2.12.91 
132)2.12|.91 
2.08 |.89 
2.06).89 


WN a a a as 
ONNWUN ~ 


Table C—2 (&. The 54 tetragraphs appearing 50 or more times, arranged in alphabetic order by initial 
letters, then by absolute frequencies, accompanied by the logarithms of assigned 
probabilities (U) 


Lio | boa 
\(F) | (F) 


134:2.13).91 
97'1.99 86 
64'1.81'.79 


140:2.15!.92 
62'1.791.78 
11.7778 


Be 
1.85:.81 
/1.83).80 


12.05 ..88 


'2.18).93 

1.89).82 ie 
1.75|.77 87:1.94'.84 
| 59'1.77:.78 
1851.81 56'1.75).77 
[1.85.81 aa 
1.75).77 

| 


7011.85:.81 


| 
| 


/1.831.80 


c-3 —CONFIDENTIAL_ — 


Table C—3 oh The 54 tetragraphs appearing SO or more times, arranged in alphabetic order by their 


second letters, and then according to’ their absolute frequencies, accompanied by the 
logarithms of their assigned probabilities (U) 


Fo Lio |4244 
(F) |) 


134:2.131.91 
66 1.82).80 
63/1.80/.79 
59:1.77 1.78 
591-77 " 


64/1.81).79 
— 


12.19/93 
59 1.71.78 
54,1.73 1.76 


11.94.84 
411.81 1.79 
56)1.75'.77 
52: 1.72).76 
168:2.23 .95 
eats) 78 


152:2.18 93 


Table C—4 (C). The 54 tetragraphs appearing 50 or more times, arranged in alphabetic order by their their 
letters, then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) 


F jLio jLoaa 
KF) |) 


93)1.97/.85 
71;185.81 


C-4 


-GONFIDENTIAL— 


Table C—4 (gf. The 54 tetragraphs appearing 50 or more times, arranged in alphabetic order by their third 
letters, then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) — Continued 


Table C—5 £€J. The 54 tetragraphs appearing 50 or more times, arranged in alphabetic order by their final 
letters, then by absolute frequencies, accompanied by the logarithms of their assigned 
probabilities (U) 


APPENDIX D (2f 
WORD AND PATTERN LISTS 


CONFIDENTFIAL—_. 


Table D—1 (Z). List of words used in military text arranged alphabetically 
according to word length (U) 


TWO LETTER WORDS 
AM BY EM IN MM OK TO 
AN CO GO IS MP ON US 
AS CP HE IT MY OR WD 
AT CQ HQ MC NO QM WE 
BE DO IF ME OF sO wo 
BN 

THREE LETTER WORDS 

ACT BIG EAT HER MIX PVT TEN 
ADD BOX END HIM NAN QMC THE 
ADJ BUT EYE HIS NET RED TIN 
AGE BUY FAR HOW NEW RID TON 
AGO CAM FEW ILL NOT ROB TOO 
AID CAN FIT ITS NOW RUN TOP 
AIM CAR FIX JIG OFF SAW TRY 
AIR CAV FOR JOB OLD SAY TUB 
ALL COL FOX KEG ONE SEA TWO 
AND CPL GAL LAW OUR SEE USE 
ANY CUT GAS LAY OUT . SET VAT 
APT CWT GEN LET OWE SGT WAR 
ARC DAY GET LOT OWN SHE WAS 
ARE DID GHQ LOW PAR SIX WAY 
ARM DIE GOT MAJ PAY SPY WET 
ASK DOG GUN MAN PEN SUM WGT 
BAD DRY HAD MAT PER SUN WON 
BAG DUE HAM MAY PIN TAN YET 
BAR DUN HAS MEN PUT TAX YOU 
BID 

FOUR LETTER WORDS 
ABLE BOTH EACH FLEE HIGH LATE MAIN 
AIDE BULB EAST FORM HILL LEAD MANY 
ALLY BULK EASY FOUR HITS LEAK MASK 
ALSO CALL EDGE FROM HOLD LEFT MASS 
AREA CELL EYES FULL HOOK LESS MEAT 
ARMY CITY FALL FUSE INTO LIEU MEET 
ASIA CODE FARM FUZE ITEM LINE MESS 
AWAY COOK FAST GUNS JOIN LIST MIKE 
AXIS DARK FEEL HALF JULY LOAD MILE 
BACK DASH FEET HALT JUNE LONG MINE 
BASE DATE FELL HAND JUST LOOK MORE 
BEEN DAYS FILE HARD KEEP LOSS MOVE 
BLUE DIRT FIRE HAVE KIND LOST MTCL 
BODY DOWN FIRM HEAD KING LOVE MULE 
BOMB DRAW FIVE HERD LAND MADE NAVY 
BOOK DUMP FLAG HERE LAST MAIM NEAR 


a — _ GONFIDENTFIAL— 


ABOUT 
AFTER 
AGAIN 
AGENT 
ALARM 
ALERT 
ALIGN 
ALINE 
ALLOW 
ALONG 
AMONG 
ANNEX 
APPLY 
APRIL 
AREAS 
ARMOR 
ASSET 
AWAIT 
AWARD 
BAKER 
BANKS 
BARGE 
BEACH 
BEGIN 
BEING 
BLACK 
BLIND 


NEXT 
NINE 
NOON 
NOTE 
OBOE 
OMIT | 
ONCE 
ONLY 
OPEN 
ORAL 
OVER 


BOATS 
BOMBS 
BOOTH 
BREAK 
BRIBE 
BROKE 
BURST 
CANAL 
CASES 
CAUSE 
CEASE 
CHECK 
CHIEF 
CLEAR 
CLERK 
CLOSE 
COAST 
COLON 
COMMA 
CORPS 
COUNT 
COVER 
CREEK 
CREST 
CROSS 
CURVE 
DAILY 


 CONFIDENTIAL- 


Table D-1 eh, List of words used in military text arranged alphabetically 
according to. word length (U)--Continued 


FOUR LETTER WORDS-— Continued 


DECKS 
DEFER 
DELAY 
DEPOT 
DEPTH 
DOCKS 
DRAWN 
DRESS 
DRILL 
DRIVE 
EAGER 
EARLY 
EIGHT 
ENEMY 
ENTER 
EQUAL 
EQUIP 
ERASE 
ERROR 
EITHER 
EVERY 
FATAL 
FEARS 
FERRY 
FIELD 
FIFTH 
FIFTY 


REAR SHOT TEAM 

RIOT SIDE TENT 

ROAD SOME TEXT 

ROUT SOON THAN 

RULE STOP THAT 

RUSH SUNK THEM 

SAID TAKE THEN 

SAME TALK THEY 

SANK TANK THIS 

SEEN TARE TIME 

SHIP TASK TONS 
FIVE LETTER WORDS 
FLIGHT LATER PRIOR 
FIRES LEAST PROOF 
FIRST LEAVE PROVE 
FLANK LEVEL QUEEN 
FLARE LIGHT QUICK 
FLATS LIMIT QUIET 
FLEET LOCAL RADIO 
FOGGY MAJOR RAFTS 
FORCE MARCH RAIDS 
FORTY . METER RALLY 
FRESH MILES RANGE 
FRONT MOTOR RAPID 
GATES NAVAL REACH 
GAUGE NIGHT READY 
GIVEN NINTH REFER 
GOING NORTH REPEL 
GROUP ORDER RIDGE 
GUARD OTHER RIGHT 
GUEST PACKS RIGID 
HEAVY PAIRS RIVER 
HONOR PARTY ROGER 
HORSE PETER ROUTE 
HOURS PLACE SCALE 
HOUSE PLAIN SEIZE 
ISSUE PLANS SEVEN 
JAPAN POINT SHELL 
LARGE PRESS SHIFT 


TOOK 
TOOL 
TOWN 
TYPE 

UNIT 

VARY 
VERY 
WEAK 
WEEK 
WELL 
WERE 


SHIPS 
SHORE 
SIEGE 
SIGHT 
SIXTH 
SIXTY 
SLOPE 
SMALL 
SMOKE 
SOUTH 
SPEED 
SPELL 
SPLIT 
SQUAD 
STAFF 
STAKE 
START 
STEEL 
SUGAR 
TAKEN 
TANKS 
TENTH 
THEIR 
THERE 
THESE 
THIRD 
THREE 


TITLE 
TODAY 
TOTAL 
TRACT 
TRAIN 
TROOP. 
TRUCE 
TRUCK 
UNDER 
UNION 
UNITS 
USUAL 
VALOR 
VISIT 
VITAL 
VOCAL 
VOICE 
WAGON 
WEIGH 
WHEEL 
WHERE 
WHICH 
WIDTH 
WIPED 
WOODS 
YARDS 
ZEBRA 


Table D-1 (ey, List of words used in military text arranged alphabetically 
according to word length (U)--Continued 


SIX LETTER WORDS 
ACCEPT BOMBED DEGREE FIERCE LESSON OTHERS RESUME SUFFER 
ACCESS BOMBER DEPART FILING LETTER OUTPUT RETIRE SUMMER 
ACROSS BOTTOM DEPEND FINISH LINING PANAMA RETURN SUMMIT 
ACTION BRANCH DEPLOY FIRING LIQUID PARADE REVIEW SUMMON 
ACTIVE BREACH DESERT FLIGHT LITTER PARLEY RIDING SUNDAY 
ADJUST BREEZE DETACH FLYING LITTLE PASSED ROCKET SUNKEN 
ADVICE BRIDGE DETAIL FOLLOW LOCATE PASSES ROUTED SUNSET 
ADVISE BROKEN DEVICE FORCES LOSSES PATROL ROUTES SUPPLY 
AFFAIR BUREAU DEVISE FORMAL MANAGE PERIOD RUBBER SURVEY 
ALASKA CANADA DIRECT FORMED MANNER _ PICKET RUNNER . SWITCH 
ALLEGE CANCEL DIVERT FOUGHT MANUAL PINCER SALARY SYSTEM 
ALLIED CANNOT DIVIDE FOURTH MEAGER PISTOL SCHEME TABLES 
ALLIES CANVAS DOCTOR FRIDAY MEDIUM PLACES SCHOOL TANKER 
ALWAYS CASUAL DOLLAR FUTURE MEMBER PLANES SCORED TARGET 
ANIMAL CAUSED DOWNED GARAGE METHOD POINTS SCREEN TATTOO 
ANNUAL CENTER DRYRUN GEORGE METRIC POISON SEAMAN TERROR 
ANYWAY CHANGE DUGOUT GREASE MINING POLICE SEAMEN THIRTY 
APPEAR CHARGE DURING GROUND MINUTE PONTON SEARCH THOUGH 
ARABIA CHEESE EFFECT GUNNER MIRROR POSTAL SECOND THREAT 
ARMIES CHURCH EFFORT HALTED MOBILE PREFER SECTOR TRAINS 
ARMORY CIPHER EIGHTH HAMMER MONDAY ~~ PROMPT SECURE TRENCH 
ARREST CIRCLE EIGHTY HAPPEN MORALE PROPER SELECT TROOPS 
ARRIVE COFFEE EITHER HARBOR MORTAR PURSUE SERIAL | TURRET 
ASSETS COLORS ELEVEN HELPER MOVING RADIAL SETTLE TWELVE 
ASSIST COLUMN EMBARK HIGHER MURDER RAIDED SEVERE TWENTY 
ASSURE COMBAT EMPLOY . HOURLY MUZZLE RATION SHELLS UNABLE 
_ ATTACH COMMIT ENCODE INDEED NAUGHT RAVINE SIGCOM UNITED 
ATTACK COMMON ENGAGE INFORM NEARER RECORD SIGNAL UNLESS 
ATTAIN CONVEY ENGINE INLAND NINETY REDUCE SINGLE VALLEY 
AUGUST CONVOY ENROLL INTEND NORMAL REFILL SLIGHT VERBAL 
BANNER COURSE ENTIRE INTENT NOTING REFUGE SPHERE VERIFY 
BARBED CREDIT ERASER INVENT NOUGHT REFUSE SPOOLS VESSEL 
BARGES CRISIS ESCORT ISLAND NOVICE REJECT SPOONS VICTIM 
BATTEN CRITIC EUROPE ISSUES NOZZLE RELIEF STATES VICTOR 
BATTLE DAMAGE EXCEPT KEEPER NUMBER REMAIN STATUS VISITS 
BEETLE DEBARK EXCESS KILLED OCCUPY REMEDY STRAFE VISUAL 
BEFORE DECIDE EXCITE LADDER OFFEND REPAIR STREET WEIGHT 
BETTER DECODE EXPECT LANDED OFFICE REPORT STRESS WIRING 
BEYOND °« DECREE EXPELS LAUNCH OPPOSE RESCUE STRIPS WITHIN 
BILLET DEFEAT EXPEND LEADER ORDERS RESIST SUBMIT WOODED 
BITTER DEFECT EXTEND LEAGUE ORIENT RESULT SUDDEN ZIGZAG 
BODIES DEFEND EXTENT 
SEVEN LETTER WORDS 

ABANDON ALMANAC APPOINT ASIATIC AVIATOR BATTERY BETWEEN 

ABSENCE AMMETER APPROVE ASSAULT AWKWARD BATTLES BICYCLE 

ADDRESS ANALYZE ARMORED ATTACKS BAGGAGE BEARING BINDING 

ADVANCE ANOTHER ARRANGE ATTEMPT BALLOON BECAUSE BIVOUAC 

AGAINST ANTENNA ARRIVAL AVERAGE BARRAGE BEDDING BOMBARD 


Table D-1 (J). List of words used in military text arranged alphabetically 


BOMBERS 
BOMBING 
BOYCOTT 
BRIBERY 
BRIGADE 
CALIBER 
CALIBRE 
CAPTAIN 
CAPTIVE. 
CARRIER 
CAVALRY 
CENTRAL 
CHANGES 
CHANNEL 
CHARLIE 
CHASSIS 
CIRCUIT 
CLIPPER 
COASTAL 
COLLECT 
COLLEGE 
COLONEL 
COMMAND 
COMMEND 
COMMENT 
COMMUTE 
COMPANY 
COMPASS 
CONCEAL 
CONDEMN 
CONDUCT 
CONFINE 
CONTACT 
CONTAIN 
CONTROL 
CORRECT 
COUNCIL 
COURIER 
COVERED 
CROSSED 
CRUISER 
CURRENT 
CYCLONE 
DAMAGED 


ACTIVITY 

ACTUALLY 
ADJACENT 
ADJUTANT 


DEBOUCH 
DECIDED 
DECLARE 
DECODED 
DEFENSE 
DELAYED 
DELIVER 
DERRICK 
DESTROY 
DETRAIN 
DETRUCK 
DEVELOP 
DIAGRAM 
DISCUSS 
DISEASE 
DISMISS 
DISTILL 
DROPPED 
EASTERN 
ECHELON . 
ELEMENT 
ELEVATE 
EMBASSY 
ENCODED 
ENEMIES 
ENFORCE 
ENGAGED 
ENTENTE 
ENTRAIN 
ENTRUCK 
ENVELOP 
EVENING 
EXCLUDE 
EXPLAIN 
EXPRESS 
EXTRACT 
EXTREME 
FALLING 
FARTHER 
FEDERAL 
FIFTEEN 
FIGHTER 
FILLING 
FINDING 


ADVANCED 
ADVANCES 
ADVISING 
ADVISORY 


GONFIDENTIAL— 


according to word length (U)--Continued 


SEVEN LETTER WORDS-— Continued 


FISHING LANDING PACKAGE 
FITTING LEADING PASSAGE 
FOGHORN LECTURE PASSIVE 
‘FORCING LIAISON PATROLS 
FORGING LIBRARY PAYROLL 
FORWARD LICENSE PLACING 
FOXHOLE LIFTING PLATOON 
FUELOIL LOADING POUNDER 
FURNISH LOGICAL PRAIRIE 
FURTHER LOOKOUT PRECEDE 
GASSING MACHINE PREPARE 
GENERAL MANDATE PRESENT 
GETTING MANNING — PRESSED 
GLASSES MAPPING PRIMARY 
GRADUAL MARCHED PROCEED 
GRENADE MARSHAL PROGRAM 
GUARDED MARTIAL PROMOTE 
HALTING MAXIMUM PROPOSE 
HASBEEN MEDICAL PROTECT 
HEADING MESSAGE PROTEST 
HEAVIER MESSING PROVOST 
HIGHEST MILITIA PURPOSE 
HOLDING MINIMUM ~ PURSUIT 
HORIZON MISFIRE PUSHING 
HOSTILE MISSING QUARTER 
HUNDRED MISSION QUICKLY 
ICEBERG: MORNING . RADIATE 
ILLEGAL NATURAL RAIDING | 
ILLNESS NEAREST RAILWAY 
INCLUDE NIGHTLY RAINING 
INFLICT | NOTHING RAPIDLY 
INITIAL NUMBERS REACHED 
INQUIRE OBSERVE RECEIPT 
INQUIRY OCTOBER RECEIVE 
INSPIRE OFFENSE RECOVER 
INSTALL OFFICER RECRUIT 
INSTANT OMITTED REDUCED 
INVADED OPERATE REFUGEE 
ISLANDS OPINION REGULAR 
ISSUING ORDERED RELEASE 
JANUARY OUTPOST RELIEVE 
JUMPOFF OUTSIDE REPAIRS 
KITCHEN PACIFIC REPLACE 
KILLING 
EIGHT LETTER WORDS 
AIRBORNE AIRPLANE ANNOUNCE 
AIRCRAFT ALTITUDE ANTITANK 
AIRDROME AMERICAN APPARENT 
AIRFIELD ANALYSIS APPEARED 


REQUEST 
REQUIRE 
RESERVE 
RESPECT 
RESPOND 
RETIRED 
RETREAT 
REVENUE 
REVERSE 
REVOLVE 
ROUTINE 
RUNNING 
SAILORS 
SATISFY 
SECRECY 
SECTION 
SECTORS 
SERVICE 
SESSION 
SETBACK 
SEVENTH 
SEVENTY 
SEVERAL 
SHELLED 
SHORTLY 
SIGNIFY 
SIMILAR 
SIMPLEX 
SINKING 
SIXTEEN 
SLOPING 
SMOKING 
SOLDIER 
STARTER 
STATION 
STEAMER 
STOPPED 
STORAGE 
SUCCESS 
SUGGEST 
SUMMARY 
SUNRISE 
SUPPORT 


APPROACH 
APPROVAL 
ARMAMENT 
ARRESTED 


SUPPOSE 
SURPLUS 
SUSPEND 
TACTICS 
TALKING 
TARGETS 
TERRAIN 
THATTHE 
THROUGH 
TOBACCO 
TONIGHT 
TONNAGE 
TORPEDO 
TRACTOR 
TRAFFIC 
TRAWLER 
TRIGGER 
TUESDAY 
TWELFTH 
UNKNOWN 
UNUSUAL 
USELESS 
UTILITY 
VACANCY 
VARYING 
VESSELS 
VICTORY 
VILLAGE 
VISIBLE 


- VISITOR 


WARFARE 
WARSHIP 
WEATHER 
WESTERN 
WHETHER 
WILLIAM 
WINDAGE 
WITHOUT 
WITHTHE 
WITNESS 
WOUNDED 
WRECKED 
WRITTEN 


ASSEMBLE 
ASSEMBLY 
ASSIGNED 

ASSOONAS 


Table D-1 [eof List of words used in military text arranged alphabetically 


ATLANTIC 
ATTACKED 
ATTEMPTS 
AVIATION 
BARRACKS 
BARRAGES 
BATTERED 
BATTLING 
BESIEGED 
BILLETED 
BOUNDARY 
BREAKING 
BUILDING 
BULLETIN 
BUSINESS 
CALAMITY 
CAMPAIGN 
CANISTER 
CAPACITY 
CAPTURED 
CARELESS 
CARRIAGE 
CARRIERS 
CARRYING 
CASUALTY 
CAUSEWAY 
CEMETERY 
CENTERED 
CHAPLAIN 
CHEMICAL 
CIRCULAR 
CITATION 
CIVILIAN 
CLERICAL 
CODEBOOK 
COMMANDS 
COMMENCE 
COMMERCE 
COMPLETE 
COMPOSED 
CONCLUDE 
CONCRETE 
CONFLICT 
CONGRESS 
CONTINUE 
CONTRACT 
CORPORAL 
CORRIDOR 
COVERING 
CRITICAL 


CRITIQUE 
CROSSING 
CRUISERS 
DAMAGING 
DARKNESS 
DAYLIGHT 
DECEMBER 
DECIPHER 
DECISION 
DECISIVE 
DECLARED 
DECREASE 
DEDICATE 
DEFEATED 
DEFENDED 
DEFENDER 
DEFENSES 
DEFERRED 
DEFINITE 
DELAYING 
DEMANDED 
DEPARTED 
DEPLOYED 
DEPORTED 
DESCRIBE 
DESERTED 
DESERTER 
DESPATCH 
DETACHED 
DETECTOR 
DETONATE. 
DEVELOPE 
DICTATED 
DICTATOR 
DIMINISH 
DIRECTOR 
DISARMED 
DISASTER 
DISLODGE 
DISPATCH 
DISPERSE 
DISTANCE 
DISTRESS 
DISTRICT 
DIVIDING 
DIVISION 
DOCTRINE 
DOMINANT 
DRESSING 


CONFIDENTIAL — 


according to word length (U)-~Continued 
EIGHT LETTER WORDS-—continued 


DRIETING 
EASTERLY 
EASTWARD 
ECONOMIC 
EFFECTED 
EFFICACY 
EIGHTEEN 
ELEMENTS 
ELEVENTH 
ELIGIBLE 
EMPLOYEE 
EMPLOYER 
ENCIPHER 
ENCIRCLE 
ENFILADE 
ENGAGING 
ENGINEER 
ENLISTED 
ENORMOUS 
ENROLLED 
ENTERING 
ENTRENCH 
ENVELOPE 
EQUALIZE 
EQUIPAGE 
ESCORTED 


- ESTIMATE 


EUROPEAN 
EVACUATE 
EXCAVATE 
EXCHANGE 
EXERCISE 
EXPANDED 
EXPEDITE 
EXPELLED 
EXPENDED 
EXPENSES 
EXTENDED 
EXTERIOR 
FACTIONS 
FATALITY 
FEBRUARY 
FERRYING 
FIGHTERS 
FIGHTING 
FINISHED 
FLANKING 
FLEXIBLE 
FOOTHOLD 


FORENOON 
FORTRESS 
FOURTEEN 
FRONTAGE 
FUSELAGE 
GARRISON 
GROUNDED 
GROUPING 
GUARDING 
HAVEBEEN 
HINDERED 
HOSPITAL 
HOWITZER 
IDENTIFY 
IGNITION 
IMPROPER 
IMPROVED 
INCIDENT 
INDICATE 
INDIRECT 
INFANTRY 
INFECTED 
INITIATE 
INSECURE 
INSIGNIA 
INSTRUCT 
INTEREST 
INTERIOR 
INTERNAL 
INTRENCH 
INVADING 
INVASION 
INVENTED 
JETPLANE 
JUNCTION 
LANGUAGE 
LATITUDE 
LETTERED 
LIMITING 
LOCATION 
LUMINOUS 
MAINTAIN 
MANDATED 
MANEUVER 
MARCHING 
MARITIME 
MATERIAL 
MATERIEL 
MECHANIC 


MEDICINE 
MEMORIAL 
MERCIFUL 
MESSAGES 
MIDNIGHT 
MILITARY 
MISFIRES 
MISSIONS 
MOBILIZE 
MONOPOLY 
MOUNTAIN 
MOVEMENT 
NATIONAL 
NAUTICAL 
NINETEEN 
NORTHERN 
NOVEMBER 
OBSERVED 
OBSERVER 
OBSOLETE 
OBSTACLE 
OCCUPIED 
OFFENDED 
OFFICERS 
OFFICIAL 
OPERATOR 
OPPOSING 


‘OPPOSITE 


ORDINATE 
ORDNANCE 
OUTBOARD 
OUTGUARD 
OUTPOSTS 
PAINTING 
PARALLAX 
PARALLEL 
PASSPORT 
PLANNING 
POLITICS 
PONTOONS 
POSITION 
POSITIVE 
POSSIBLE 
POSTPONE 
PREPARED 
PRESERVE 
PRESSING 
PRESSURE 
PRINTING 


PRIORITY 
PRISONER 
PROBABLE 
PROBABLY 
PROGRESS 
PROHIBIT 
PROTESTS 
PROTOCOL 
PURPOSES 
QUARTERS 
RAILHEAD 
RAILROAD 
RALLYING 
RECEIVER 
RECORDER 
REDCROSS 
REENLIST 
REGIMENT 
REGISTER 
REJECTED 
REJECTOR 
REMEDIES 
REMEMBER 
REPAIRED 
REPEATER 
REPELLED 
REPLACED 
REPORTED 
REPULSED 
REQUIRED 
RESEARCH 
RESERVES 
RESPECTS 
RESTORED 
RETIRING 
RETURNED 
REVIEWED 
REVOLVER 
RIGOROUS 
SABOTAGE 
SANITARY 
SATURDAY 
SCHEDULE 
SEABORNE 
SEALEVEL 
SELECTED 
SENTENCE 
SENTINEL 
SEPARATE 


SERGEANT 
SHELLING 
SHIPPING 
SIGHTING 
SKIRMISH 
SOLDIERS 
SOUTHERN 
SPECIFIC 
SPOTTING 
SQUADRON 
STANDARD 
STATIONS 
STRATEGY 
SUFFERED 
SUITABLE 
SUPERIOR 
SUPPLIES 
SURPRISE 
SURROUND 
SURVIVED 
SUSPENSE 
SWEEPING 
SWIMMING 
TACTICAL 
TAXATION 
TELEGRAM 
TERRIBLE . 
TERRIFIC 
THATHAVE 
THIRTEEN 
THOUSAND 
THURSDAY 
TOMORROW 
TOTALING 
TRAILERS 
TRAINING 
TRANSFER 
TRAVERSE 
TRAWLERS 
VEHICLES 
VICINITY 
VIGOROUS 
WARSHIPS 
WESTERLY 
WESTWARD 
WINDWARD 
WIRELESS 
WITHDRAW 
WITHDREW 


-CONFIDENTFIAL— 


Table D=-1 (2%. List of words used in military text arranged alphabetically 
according to word length (U)-~Continued 


NINE LETTER WORDS 
ACCESSORY CENTERING DEVELOPED FORMATION MOVEMENTS PRO 
ACCOMPANY CHALLENGE DIETITIAN FORTIFIED MUNITIONS PROTESTED 
ACCORDING CHARACTER DIFFERENT FRONTLINE NAVALBASE PROVISION 
ADDRESSED CHAUFFEUR DIFFICULT GROUPMENT NECESSARY PROXIMITY 
ADDRESSES CHRONICAL DIMENSION GYROMETER NECESSITY RADIATION . 
ADMISSION CIGARETTE DIRECTION HOSTILITY NEGLIGENT RADIOGRAM 
ADVANCING CIRCULATE  DIRIGIBLE HURRICANE NEWSPAPER READINESS 
ADVANTAGE CIVILIANS DISAPPEAR IDENTICAL NORTHEAST REARGUARD 
AERODROME CLEARANCE DISCUSSED IMMEDIATE NORTHERLY REBELLION 
AEROPLANE COALITION DISINFECT IMPORTANT NORTHWARD RECEIVING 
AFTERNOON COLLAPSED DISMISSAL IMPRESSED NORTHWEST RECOGNIZE 
AGREEMENT COLLISION DISPERSED INCENTIVE NUMBERING RECOMMEND 
AIRDROMES COMBATANT DISTRICTS INCIDENCE OBJECTION REENFORCE 
AIRPLANES COMMANDED DIVISIONS INCIDENTS OBJECTIVE REFERENCE 
ALLOTMENT COMMANDER DOMINANCE — INCLINING OBTAINING REFILLING 
ALLOWANCE COMMITTEE DOMINATED INCLUDING OCCUPYING REGARDING 
ALTERNATE COMPANIES ECHELONED INCLUSIVE OFFENSIVE REINFORCE 
AMBULANCE COMPELLED EFFECTIVE INCREASED OFFICIALS REINSTATE 
AMUSEMENT COMPLETED EFFICIENT INDEMNITY OPERATING REMAINDER 
ANNOUNCED CONDEMNED ELABORATE INDICATED OPERATION REMAINING 
ANONYMOUS CONDENSED ELEVATION INFLATION OSCILLATE REPRESENT 
APPARATUS CONDITION ELSEWHERE INFLICTED OUTSKIRTS REPRISALS 
APPOINTED CONFERRED EMBASSIES INFLUENCE PARACHUTE REQUESTED 
ARBITRARY CONFIDENT EMERGENCY INHABITED PARAGRAPH REQUIRING 
ARTILLERY CONFLICTS EMPLOYING INSTANTLY PARTITION RESOURCES 
ASCENSION CONQUERED ENDURANCE INTEGRITY PASSENGER RESTRAINT 
ASSAULTED CONTINUAL ENGINEERS INTENSIVE PATRIOTIC RETENTION 
ASSISTANT CONTINUED — ENLISTING INTENTION PENETRATE RETURNING 
ASSOCIATE ~ CONTINUES ENTRAINED INTERCEPT PERMANENT REVIEWING 
ASSURANCE COOPERATE EQUIPMENT INTERDICT PERSONNEL SCREENING 
ATTACKING CORRECTED ESTABLISH INTERFERE PLACEMENT SEAPLANES 
ATTEMPTED ~ CRITICISE ESTIMATED INTERMENT POLITICAL SECRETARY 
ATTENTION CRITICISM ESTIMATES INTERPOSE POPULATED SEMICOLON 
AUTOMATIC DEBARKING EXCESSIVE INTERRUPT — POSITIONS SEMIRIGID 
AVAILABLE DECREASED EXCLUSION INTERVENE PRACTICAL SEPTEMBER 
BALLISTIC DEFECTIVE EXCLUSIVE INTERVIEW PRECEDING SERIOUSLY 
BAROMETER DEFENSIVE EXECUTIVE INVENTION PREFERRED SERVICING 
BATTALION DEFICIENT EXERCISES IRREGULAR PREMATURE SEVENTEEN 
BATTERIES DEPARTURE EXHIBITED KILOMETER PREPARING SHELLFIRE 
BEACHHEAD. DEPENDENT EXPANSION LAUNCHING PRESIDENT SITUATION 
BEGINNING DESCRIBED EXPANSIVE LIABILITY PRINCIPAL SIXTEENTH 
BLOCKADED DESIGNATE EXPENSIVE LOGISTICS PRINCIPLE SOUTHEAST 
BOMBARDED DESTITUTE EXPLOSION LONGITUDE PRISONERS SOUTHWARD 
BRIGADIER DESTROYED EXPLOSIVE MAINTAINS PROCEDURE SOUTHWEST 
BUILDINGS DESTROYER EXTENDING MANGANESE PROCEEDED SPEARHEAD 
CABLEGRAM DETENTION EXTENSION MECHANISM PROJECTOR STANDARDS 
CAMPAIGNS DETERMINE EXTENSIVE MEMORANDA PROMOTION STATEMENT 
CANCELLED | DETONATED FIFTEENTH MESSENGER PROPOSALS STRAGGLER 
CARTRIDGE DETRAINED FIREALARM MOTORIZED PROTECTED STRATEGIC 


Table D-1 (2%, List of words used in military text arranged alphabetically 
according to word length (U)--Continued 


NINE LETTER WORDS-— Continued 


D-8 


SUBMITTED SUSPENDED TELEPHONE THEREFORE UNTENABLE WEDNESDAY 

SUCCEEDED SUSPICION | TENTATIVE TRANSPORT VARIATION WITNESSES 

SURRENDER TECHNICAL TERRITORY TWENTIETH WATERTANK YESTERDAY 

SUSPECTED TECHNIQUE 

TEN LETTER WORDS 

ACCEPT ABLE COLLISIONS DESPT ACHES EXPENDABLE MAINTAINED 
ACCEPTANCE COMMANDANT DESTROYERS EXPERIENCE - MANAGEMENT 
ACCIDENTAL COMMANDEER DETACHMENT EXPERIMENT MECHANIZED 
ACCORDANCE COMMANDING DETERMINED EXPLOSIONS MEMORANDUM 
ACTIVITIES COMMISSARY DETONATION EXTINGUISH MILLIMETER 
ADDITIONAL COMMISSION DETRAINING FACILITIES MOTORCYCLE 
AIRCONTROL COMMITMENT DETRUCKING FLASHLIGHT NATURALIZE 
AIRSUPPORT COMMUNIQUE DIFFERENCE FORMATIONS NAVIGATION 
ALLEGIANCE COMPENSATE DIPLOMATiC FOUNDATION NEGLIGENCE 
ALLOCATION COMPLETELY DIRECTIONS FOURTEENTH NEWSPAPERS 
AMBASSADOR COMPRESSED DISCIPLINE FRONTLINES NINETEENTH 
AMMUNITION CONCERNING DISCUSSION GEOGRAPHIC OBJECTIVES 
ANTEDATING CONCESSION DISPATCHED GONIOMETER OCCUPATION 
ANTICIPATE CONCLUSION DISPATCHER GOVERNMENT ONEHUNDRED 
APPARENTLY CONDITIONS DISPATCHES GYROSCOPIC OPERATIONS 
APPEARANCE CONFERENCE DISPERSION HYDROMETER OPPOSITION 
APPROACHED CONFESSION DISTRESSED HYGROMETER OVERCOMING 
ARMOREDCAR CONFIDENCE DISTRIBUTE ILLITERATE PATROLLING 
ARTIFICIAL CONNECTING DIVEBOMBER ILLUMINATE PERMISSION 
ASPOSSIBLE CONNECTION DOMINATION ILLUSTRATE PERSISTENT 
ASSEMBLIES CONSPIRACY EFFICIENCY IMPASSABLE PHOSPHORUS 
ASSESSMENT CONSTITUTE EIGHTEENTH IMPOSSIBLE POPULATION 
ASSIGNMENT CONTINGENT ELEMENTARY IMPRESSION POSSESSION 
ASSISTANCE CONTINUOUS EMPLOYMENT IMPRESSIVE POSTOFFICE 
ATOMICBOMB CONTRABAND ENCIPHERED INCENDIARY PRECEDENCE 
ATTACHMENT CONVENIENT ENCIRCLING INDICATING PREFERENCE 
ATTAINMENT COORDINATE ENEMYTANKS INDICATION PRESCRIBED 
ATTEMPTING CORRECTION ENGAGEMENT INDIVIDUAL PROHIBITED 
AUDIBILITY CREDENTIAL ENLISTMENT INFLICTING PROPORTION 
AUTOMOBILE CROSSROADS ENROLLMENT INSECURITY PROTECTION 
BALLISTICS DEBOUCHING ENTERPRISE INSPECTION PROVISIONS 
BATTLESHIP DECIPHERED ENTRENCHED INSTRUCTED QUARANTINE 
BEENNEEDED DECORATION ENTRUCKING INSTRUCTOR RECEPTACLE 
BRIDGEHEAD DEDICATION EQUIVALENT INSTRUMENT RECREATION 
CAMOUFLAGE DEFICIENCY ESTIMATION INTERNMENT RECRUITING 
CAPABILITY DEFINITION EVACUATING INVITATION REENFORCED 
CASUALTIES DEMOBILIZE EVACUATION IRRIGATION REENLISTED 
CENSORSHIP DEPARTMENT EVALUATION KILOMETERS REGIMENTAL 
CENTRALIZE DEPENDABLE EXCAVATION LABORATORY REGULATION 
CIRCUITOUS DEPLOYMENT EXCITEMENT LIEUTENANT REINFORCED 
COASTGUARD DEPRESSION EXHIBITION LIMITATION RESISTANCE 
COLLECTING DESIGNATED EXPEDITING LOCOMOTIVE RESPECTFUL 
COLLECTION DESPATCHED EXPEDITION MACHINEGUN RESTRICTED 


-CONFIDENTIAL — 


Table D-1 1 &. List of words used in military text arranged alphabetically 
according to word length (U)--Continued 


TEN LETTER WORDS— Continued 


REVOLUTION SUBMISSION SUSPENSION TRANSPORTS UNEXPENDED 
SANITATION SUBSTITUTE SUSPICIONS TRANSVERSE UNSUITABLE 
SEPARATION SUCCESSFUL SUSPICIOUS TROOPSHIPS VICTORIOUS 
SIGNALLING SUCCESSIVE THIRTEENTH TWENTYFIVE VISIBILITY 
SIMILARITY SUFFICIENT THREATENED UNDERSTAND WILLATTACK 
STATISTICS SUPPORTING TRAJECTORY UNDERSTOOD WITHDRAWAL 
SUBMARINES 

ELEVEN LETTER WORDS 
ACCESSORIES CONCEALMENT EMBARKATION INTERCEPTED REAPPOINTED 
AERONAUTICS CONCENTRATE EMPLACEMENT INTERESTING RECOGNITION 
ACKNOWLEDGE CONFINEMENT ENCOUNTERED INTERFERING RECOMMENDED 
ALTERNATING CONSTITUTED ENEMYPLANES INTERPRETER RECONNOITER 
APPLICATION CONSUMPTION ENFORCEMENT INTERRUPTED REPLACEMENT 
APPOINTMENT CONTINENTAL ENGAGEMENTS INTERVENING REQUIREMENT 
APPROACHING CONTROVERSY ENGINEERING INVESTIGATE REQUISITION 
APPROPRIATE COOPERATION ESTABLISHED LEGISLATION RESERVATION 
APPROXIMATE CORPORATION ESTIMATEDAT LIGHTBOMBER RESIGNATION 
ARBITRATION CORRECTNESS EXAMINATION MAINTENANCE RESPONSIBLE 
ARMOREDCARS CREDENTIALS EXPLANATION MANUFACTURE RESTRICTION - 
ARRANGEMENT CUSTOMHOUSE EXTENSIVELY MEASUREMENT RETALIATION 
ASSESSMENTS DEBARKATION EXTERMINATE NATIONALISM RETROACTIVE 
ASSIGNMENTS DEMONSTRATE FINGERPRINT NATIONALITY SCHOOLHOUSE 
ASSOCIATION . DESCRIPTION FIRECONTROL NAVALATTACK SEVENTEENTH 
BATTLEFIELD DESCRIPTIVE HEAVYBOMBER NAVALBATTLE SEVENTYFIVE 
BATTLESHIPS DESIGNATION HEAVYLOSSES NAVALFORCES SIGNIFICANT 
BELLIGERENT DESTRUCTION HOSTILITIES NECESSITATE SMOKESCREEN 
BLOCKBUSTER DETERIORATE IMMEDIATELY OBSERVATION STRATEGICAL 
BOMBARDMENT DEVELOPMENT IMMIGRATION OVERWHELMED SUBSISTENCE 
CATASTROPHE DISAPPEARED IMPEDIMENTA PARENTHESES SUITABILITY 
CERTIFICATE DISCONTINUE IMPROVEMENT PARENTHESIS SUPERIORITY 
CIRCULATION DISCREPANCY INCOMPETENT PENETRATION SURRENDERED 
COEFFICIENT DISINFECTED INDEPENDENT PERFORMANCE SYNCHRONIZE 
COINCIDENCE DISPOSITION INFLAMMABLE PHILIPPINES TEMPERATURE 
COMMUNICATE DISTINCTION INFORMATION PHOTOGRAPHY THERMOMETER 
COMMUNIQUES DISTINGUISH INSPIRATION PREARRANGED TOPOGRAPHIC 
COMPARTMENT DYNAMOMETER INSTITUTION PREPARATION TRADITIONAL 
COMPETITION ECHELONMENT INSTRUCTION PRELIMINARY TRANSFERRED 
COMPOSITION EFFECTIVELY INSTRUMENTS PROGRESSIVE WITHDRAWING 
COMPUTATION ELECTRICITY INTELLIGENT RANGEFINDER 

TWELVE LETTER WORDS 
ADVANTAGEOUS  CARELESSNESS CONCENTRATED CONSIDERABLE COORDINATION 
AGRICULTURAL COMMENCEMENT CONCILIATION CONSTITUTING DECENTRALIZE 
ANNOUNCEMENT COMMENDATION CONFIDENTIAL CONSTITUTION DECIPHERMENT 
ANTIAIRCRAFT COMMISSIONED CONFIRMATION CONSTRUCTION DEMONSTRATED 
ANTICIPATION COMMISSIONER CONFISCATION CONTINUATION DEPARTMENTAL 
BREAKTHROUGH COMPENSATION CONFORMATION © CONVALESCENT DIFFICULTIES 
CANCELLATION COMPLETENESS CONVERSATION DISORGANIZED 


CONSCRIPTION 


~CONFIDENTIAL — Ds 


-GONFIDENTIAL— 


Table D-1 Cae List of words used in military text arranged alphabetically 


according to word length (U)-=-Continued 


TWELVE LETTER WORDS—Continued 


DISPLACEMENT HYDROGRAPHIC INTERVENTION PREPAREDNESS SHARPSHOOTER 
DISSEMINATED ILLUMINATING INTRODUCTION PRESERVATION SIGNIFICANCE 
DISTRIBUTING ILLUMINATION INTRODUCTORY PRESIDENTIAL SIMULTANEOUS 
DISTRIBUTION ILLUSTRATION IRREGULARITY PROCLAMATION SOUTHWESTERN 
EMPLACEMENTS INAUGURATION LIGHTBOMBERS PSYCHROMETER SUBSTITUTION 
ENCIPHERMENT INCOMPETENCE MARKSMANSHIP RADIOSTATION SUCCESSFULLY 
ENTANGLEMENT INEFFICIENCY MEASUREMENTS RECREATIONAL TRANSFERRING 
ENTERPRISING INSTRUCTIONS MEDIUMBOMBER REENLISTMENT TRANSMISSION 
FIGHTERPLANE INTELLIGENCE MOBILIZATION REGISTRATION TRANSPACIFIC 
GENERALALARM INTERCEPTION NONCOMBATANT REPLACEMENTS UNIDENTIFIED 
GENERALSTAFF INTERDICTION NORTHWESTERN RESPECTFULLY UNITEDSTATES 
GEOGRAPHICAL INTERFERENCE OBSTRUCTIONS ROADJUNCTION UNSUCCESSFUL 
HEADQUARTERS INTERMEDIATE ORGANIZATION SATISFACTORY VERIFICATION 
HEAVYBOMBERS INTERRUPTION PREPARATIONS SEARCHLIGHTS VETERINARIAN 
THIRTEEN LETTER WORDS 
ACCOMMODATION CORRESPONDING DISTINGUISHED INSTANTANEOUS REAPPOINTMENT 
APPROXIMATELY COUNTERATTACK ENTERTAINMENT INTERNATIONAL REENFORCEMENT 
CHRONOLOGICAL DECENTRALIZED ESTABLISHMENT INVESTIGATION REIMBURSEMENT 
CIRCUMSTANCES DEMONSTRATION EXTERMINATION MEDIUMBOMBERS REINFORCEMENT 
COMMUNICATION DEPENDABILITY EXTRAORDINARY MISCELLANEOUS REINSTATEMENT 
CONCENTRATING DETERMINATION FIGHTERPLANES PRELIMINARIES REVOLUTIONARY 
CONCENTRATION DISAPPEARANCE IMPRACTICABLE QUALIFICATION . SPECIFICATION 
CONGRESSIONAL. DISCREPANCIES INDETERMINATE QUARTERMASTER - TRANSATLANTIC” 
CONSIDERATION DISSEMINATION INSTALLATIONS : 
FOURTEEN LETTER WORDS 
ADMINISTRATION DEMOBILIZATION IRREGULARITIES RECONSTRUCTION 
ADMINISTRATIVE DISCONTINUANCE METEOROLOGICAL REORGANIZATION 
CENTRALIZATION DISTINGUISHING NATURALIZATION REPRESENTATIVE 
CHARACTERISTIC IDENTIFICATION RECOMMENDATION RESPONSIBILITY 
CIRCUMSTANTIAL INTERPRETATION RECONNAISSANCE SATISFACTORILY 
CLASSIFICATION INVESTIGATIONS RECONNOITERING TRANSPORTATION 
CORRESPONDENCE 
pH —CONFIDENTIAL — 


-~GONFIDENTIAL _ 


Table D—2 . List of words used in military text arranged alphabetically 
in reverse order according to word length (U) 


THREE LETTER WORDS 


SEA SEE MAJ TAN TOP EAT BUT FIX 
JOB AGE ADJ GEN GHQ MAT CUT MIX 
ROB SHE ASK MEN BAR VAT OUT SIX 
TUB THE GAL PEN CAR ACT PUT BOX 
QMC DIE ALL TEN FAR GET PVT FOX 
ARC ONE ILL PIN PAR LET CWT DAY 
BAD ARE COL TIN WAR NET YOU LAY 
HAD USE CPL TON HER SET CAV MAY 
ADD DUE CAM WON PER WET LAW PAY 
RED OWE HAM DUN AIR YET SAW SAY 
AID EYE AIM GUN FOR SGT FEW WAY 
BID OFF HIM RUN OUR WGT NEW ANY 
DID BAG ARM SUN GAS . FIT HOW SPY 
RID KEG SUM OWN HAS GOT LOW DRY 
OLD BIG CAN AGO WAS LOT NOW TRY 
AND JIG MAN TOO HIS NOT TAX BUY 
END DOG NAN TWO ITS APT 

FOUR LETTER WORDS 
AREA MIKE BASE WEEK WELL NOON PASS LIST 
ASIA YOKE FUSE TALK HILL SOON LESS LOST 
BULB ABLE DATE BULK WILL DOWN MESS POST 
BOMB . FILE LATE RANK FULL TOWN LOSS JUST 
HEAD - MILE NOTE - SANK | TOOL ZERO. HITS ROUT 
LEAD MULE BLUE TANK TEAM ALSO DAYS NEXT 
LOAD RULE HAVE SUNK THEM INTO MEAT TEXT 
ROAD SAME FIVE BOOK ITEM KEEP THAT LIEU 
RAID TIME LOVE COOK MAIM SHIP WHAT DRAW 
SAID SOME MOVE HOOK FROM DUMP FEET XRAY 
HOLD LINE FUZE LOOK FARM PUMP MEET AWAY 
HAND MINE HALF TOOK FIRM STOP LEFT BODY 
LAND NINE FLAG DARK FORM NEAR OMIT THEY 
KIND ZONE KING PARK THAN REAR UNIT ALLY 
HARD JUNE LONG MASK PLAN OVER HALT ONLY 
HERD OBOE EACH TASK BEEN FOUR TENT JULY 
ONCE PIPE HIGH ORAL SEEN YOUR SHOT ARMY 
MADE TYPE DASH MTCL THEN EYES RIOT MANY 
AIDE TARE PUSH FEEL WHEN THIS DIRT VARY 
SIDE HERE RUSH RAIL OPEN AXIS EAST VERY 
CODE WERE WITH CALL MAIN TONS FAST EASY 
FLEE FIRE BOTH FALL RAIN . GUNS LAST CITY 
EDGE WIRE LEAK CELL JOIN MASS WEST NAVY 
TAKE MORE BACK FELL 


468-095 O- 72-18 


Table D-2 ee. List of words used in military text arranged alphabetically 
in reverse order according to word length (U)--Continued 


FIVE LETTER WORDS 
COMMA SCALE ALONG CANAL WAGON PRIOR DRESS START 
ZEBRA TITLE AMONG FATAL UNION MAJOR PRESS ALERT 
SQUAD ALINE BEACH: VITAL COLON VALOR CROSS LEAST 
SPEED SLOPE REACH TOTAL DRAWN ARMOR FLATS COAST 
WIPED FLARE WHICH EQUAL RADIO HONOR BOATS CREST 
RIGID THERE MARCH USUAL EQUIP ERROR RAFTS GUEST 
RAPID WHERE WEIGH NAVAL TROOP MOTOR UNITS FIRST 
FIELD SHORE FRESH WHEEL GROUP AREAS TRACT BURST 
BLIND CEASE WIDTH STEEL CLEAR BOMBS FLEET ABOUT 
GUARD ERASE FIFTH REPEL SUGAR RAIDS QUIET ALLOW 
AWARD THESE TENTH LEVEL UNDER WOODS ASSET ANNEX 
THIRD CLOSE NINTH APRIL ORDER YARDS SHIFT TODAY 
BRIBE HORSE BOOTH SMALL DEFER MILES EIGHT DELAY 
PLACE CAUSE DEPTH SHELL REFER FIRES FIGHT READY 
VOICE HOUSE NORTH SPELL EAGER ’ CASES LIGHT FOGGY 
FORCE ROUTE SOUTH DRILL ROGER GATES NIGHT DAILY 
TRUCE ISSUE SIXTH ALARM ETHER PACKS RIGHT RALLY 
THREE LEAVE BREAK JAPAN OTHER DECKS SIGHT APPLY 
RIDGE DRIVE BLACK QUEEN BAKER DOCKS AWAIT EARLY 
SIEGE PROVE CHECK TAKEN LATER BANKS SPLIT ENEMY 
RANGE CURVE QUICK SEVEN METER TANKS LIMIT EVERY 
BARGE SEIZE TRUCK GIVEN PETER PLANS VISIT FERRY 
LARGE - CHIEF CREEK ALIGN AFTER SHIPS AGENT FIFTY 
GAUGE STAFF FLANK AGAIN ENTER CORPS POINT PARTY 
STAKE PROOF CLERK PLAIN RIVER FEARS FRONT FORTY 
SMOKE BEING LOCAL TRAIN COVER PAIRS COUNT SIXTY 
BROKE GOING VOCAL BEGIN THEIR HOURS DEPOT HEAVY 
SIX LETTER WORDS 


CANADA HALTED DEVICE CHARGE SEVERE ARRIVE TRENCH MANUAL 
ARABIA ROUTED NOVICE GEORGE RETIRE ACTIVE LAUNCH ANNUAL 
ALASKA LIQUID FIERCE REFUGE ENTIRE TWELVE SEARCH CASUAL 
PANAMA INLAND REDUCE MORALE BEFORE BREEZE CHURCH VISUAL 
METRIC ISLAND PARADE UNABLE SECURE RELIEF SWITCH CANCEL 


CRITIC DEFEND DECIDE CIRCLE ASSURE ZIGZAG THOUGH VESSEL 
BOMBED OFFEND DIVIDE SINGLE FUTURE RIDING FINISH DETAIL 
BARBED DEPEND DECODE MOBILE GREASE FILING EIGHTH REFILL 


RAIDED EXPEND ENCODE BEETLE CHEESE LINING FOURTH ENROLL 
LANDED INTEND COFFEE BATTLE ADVISE MINING ATTACK SCHOOL 
WOODED EXTEND DECREE SETTLE DEVISE FIRING DEBARK PATROL 
INDEED SECOND DEGREE LITTLE OPPOSE WIRING EMBARK PISTOL 

ALLIED BEYOND STRAFE NOZZLE COURSE DURING VERBAL SYSTEM 
KILLED GROUND ENGAGE MUZZLE REFUSE NOTING RADIAL VICTIM 

FORMED METHOD DAMAGE SCHEME LOCATE MOVING SERIAL SIGCOM 
DOWNED PERIOD MANAGE RESUME EXCITE FLYING ANIMAL BOTTOM 
SCORED RECORD GARAGE ENGINE MINUTE BREACH FORMAL INFORM 
PASSED OFFICE BRIDGE RAVINE RESCUE DETACH NORMAL MEDIUM 
CAUSED POLICE ALLEGE EUROPE LEAGUE ATTACH SIGNAL SUDDEN 
UNITED ADVICE CHANGE SPHERE PURSUE BRANCH POSTAL SCREEN 


D-12 ~GONFIDENTIAL— 


in reverse order according to word length (U)--Continued 


-GONFIDENTIAL— 


Table D-2 (oh, List of words used in military text arranged alphabetically 


SIX LETTER WORDS—Continued 


SUNKEN MORTAR RUNNER FORCES COLORS TARGET CANNOT MONDAY 
BROKEN RUBBER KEEPER BARGES ACCESS PICKET ACCEPT SUNDAY 
SEAMEN MEMBER HELPER BODIES EXCESS ROCKET EXCEPT ANYWAY 
HAPPEN BOMBER PROPER ALLIES UNLESS BILLET PROMPT REMEDY 
BATTEN NUMBER NEARER ARMIES STRESS TURRET DEPART VALLEY 
ELEVEN PINCER ERASER TABLES ACROSS SUNSET DESERT PARLEY 
REMAIN LEADER CENTER PLANES ASSETS WEIGHT DIVERT CONVEY 
ATTAIN LADDER BETTER PASSES VISITS FLIGHT ESCORT SURVEY 
WITHIN MURDER LETTER LOSSES POINTS SLIGHT EFFORT VERIFY 
COLUMN PREFER BITTER STATES STATUS NAUGHT REPORT SUPPLY 
RATION SUFFER LITTER ROUTES ALWAYS FOUGHT ARREST HOURLY 
ACTION  MEAGER AFFAIR ISSUES COMBAT NOUGHT RESIST DEPLOY 
COMMON HIGHER REPAIR CRISIS DEFEAT CREDIT ASSIST EMPLOY 
SUMMON CIPHER HARBOR SHELLS THREAT SUBMIT AUGUST CONVOY 
POISON EITHER TERROR SPOOLS DEFECT COMMIT ADJUST OCCUPY 
LESSON TANKER MIRROR TRAINS EFFECT SUMMIT DUGOUT SALARY 
PONTON HAMMER ~~ SECTOR SPOONS REJECT RESULT OUTPUT ARMORY 
RETURN SUMMER VICTOR STRIPS SELECT ORIENT BUREAU NINETY 
DRYRUN BANNER DOCTOR TROOPS EXPECT INTENT REVIEW EIGHTY 
TATTOO MANNER CANVAS ORDERS DIRECT EXTENT FOLLOW TWENTY 
APPEAR GUNNER PLACES OTHERS STREET INVENT FRIDAY THIRTY 
DOLLAR 
SEVEN LETTER WORDS 
MILITIA RETIRED WINDAGE DECLARE COMMUTE FISHING VARYING 
ANTENNA ARMORED BAGGAGE PREPARE REVENUE PUSHING ICEBERG 
ALMANAC PRESSED PACKAGE CALIBRE RELIEVE NOTHING DEBOUGH 
BIVOUAC CROSSED VILLAGE MISFIRE RECEIVE TALKING THROUGH 
TRAFFIC OMITTED TONNAGE _ INSPIRE PASSIVE SINKING FURNISH 
PACIFIC DELAYED AVERAGE REQUIRE CAPTIVE SMOKING TWELFTH 
ASIATIC COMMAND STORAGE [INQUIRE REVOLVE FALLING SEVENTH 
REDUCED COMMEND BARRAGE LECTURE APPROVE FILLING SETBACK 
INVADED SUSPEND PASSAGE RELEASE OBSERVE KILLING DERRICK 
DECIDED RESPOND MESSAGE DISEASE RESERVE EVENING DETRUCK 
DECODED BOMBARD COLLEGE SUNRISE ANALYZE RAINING ENTRUCK 
ENCODED AWKWARD ARRANGE — LICENSE JUMPOFF MANNING MEDICAL 
WOUNDED FORWARD WITHTHE DEFENSE BOMBING RUNNING LOGICAL 
GUARDED REPLACE THATTHE OFFENSE PLACING MORNING CONCEAL 
PROCEED SERVICE CHARLIE PROPOSE FORCING  SLOPING ILLEGAL 
ENGAGED ADVANCE PRAIRIE SUPPOSE HEADING MAPPING MARSHAL 
DAMAGED ABSENCE VISIBLE PURPOSE LEADING BEARING INITIAL 
REACHED ENFORCE BICYCLE REVERSE LOADING  GASSING MARTIAL 
MARCHED BRIGADE HOSTILE BECAUSE BEDDING MESSING FEDERAL 
WRECKED GRENADE EXTREME MANDATE RAIDING MISSING GENERAL 
SHELLED PRECEDE CONFINE RADIATE HOLDING — LIFTING SEVERAL 
DROPPED OUTSIDE MACHINE OPERATE LANDING  HALTING CENTRAL 
STOPPED INCLUDE ROUTINE ELEVATE BINDING GETTING NATURAL 
HUNDRED EXCLUDE CYCLONE ENTENTE FINDING FITTING COASTAL 
ORDERED REFUGEE WARFARE PROMOTE FORGING ISSUING GRADUAL 
COVERED 
—GONFIDENTIAL _ D-13 


D-14 


UNUSUAL 
ARRIVAL 
CHANNEL 
COLONEL 
COUNCIL 
FUELOIL 
INSTALL 
DISTILL 
PAYROLL 
CONTROL 
WILLIAM 
DIAGRAM 
PROGRAM 
MINIMUM 
MAXIMUM 
HASBEEN 
FIFTEEN 
SIXTEEN 
BETWEEN 
KITCHEN 
WRITTEN 
EXPLAIN 
TERRAIN 
DETRAIN 


INSIGNIA 
SPECIFIC 
TERRIFIC 
ECONOMIC 
MECHANIC 
ATLANTIC 
RAILHEAD 
RAILROAD 
REPLACED 
ADVANCED 
DEMANDED 
EXPANDED 
DEFENDED 
OFFENDED 
EXPENDED 
EXTENDED 
GROUNDED 
BESIEGED 
DETACHED 
FINISHED 
OCCUPIED 
ATTACKED 
REPELLED 


-CONFIDENTIAL— 


Table D-2 , List of words used in military text arranged alphabetically 


in reverse order according to word length (U)--Continued 
SEVEN LETTER WORDS—Continued 


ENTRAIN 
CONTAIN 
CAPTAIN 
CONDEMN 
ABANDON 
OPINION 
SESSION 
MISSION 
STATION 
SECTION 
ECHELON 
BALLOON 
PLATOON 
LIAISON 
HORIZON 
EASTERN 
WESTERN 
FOGHORN 
UNKNOWN 
TOBACCO 
TORPEDO 
WARSHIP 
DEVELOP 


EXPELLED 
ENROLLED 
DISARMED 
ASSIGNED 
RETURNED 
APPEARED 
DECLARED 
PREPARED 
HINDERED 
SUFFERED 
CENTERED 
BATTERED 
LETTERED 
REPAIRED 
REQUIRED 
RESTORED 
DEFERRED 
CAPTURED 
REPULSED 
COMPOSED 
MANDATED 
DEFEATED 
REPEATED 


ENVELOP 
SIMILAR 
REGULAR 
CALIBER 
OCTOBER 
OFFICER 
POUNDER 
TRIGGER 
WEATHER 
WHETHER 
ANOTHER 
FARTHER 
FURTHER 
SOLDIER 
CARRIER 
COURIER 
HEAVIER 
TRAWLER 
STEAMER 
CLIPPER 
CRUISER 
AMMETER 
FIGHTER 


STARTER 
QUARTER 
DELIVER 
RECOVER 
AVIATOR 
TRACTOR 
VISITOR 
TACTICS 
ISLANDS 
CHANGES 
ENEMIES 
BATTLES 
GLASSES 
CHASSIS 
ATTACKS 
VESSELS 
PATROLS 
BOMBERS 
NUMBERS 
REPAIRS 
SAILORS 
SECTORS 
COMPASS 


SUCCESS 
USELESS 
ILLNESS 
WITNESS 
ADDRESS 
EXPRESS 
DISMISS 
DISCUSS 
TARGETS 
SURPLUS 
RETREAT 
EXTRACT 
CONTACT 
COLLECT 
RESPECT 
CORRECT 
PROTECT 
INFLICT 
CONDUCT 
TONIGHT 
CIRCUIT 
RECRUIT 
PURSUIT 


EIGHT LETTER WORDS 


DICTATED 
EFFECTED 
INFECTED 
REJECTED 
SELECTED 
BILLETED 
INVENTED 
DEPARTED 
DESERTED 
ESCORTED 
DEPORTED 
REPORTED 
ARRESTED 
ENLISTED 
SURVIVED 
IMPROVED 
OBSERVED 
REVIEWED 
DEPLOYED 
AIRFIELD 
FOOTHOLD 
THOUSAND 
SURROUND 


STANDARD 


OUTBOARD 
OUTGUARD 
WINDWARD 
EASTWARD 
WESTWARD 
DESCRIBE 
ORDNANCE 
DISTANCE 
COMMENCE 
SENTENCE 
ANNOUNCE 
COMMERCE 
ENFILADE 
CONCLUDE 
LATITUDE 
ALTITUDE 
EMPLOYEE 
CARRIAGE 
FUSELAGE 
EQUIPAGE 
FRONTAGE 
SABOTAGE 


LANGUAGE 
DISLODGE 
EXCHANGE 
PROBABLE 
SUITABLE 
ELIGIBLE 
TERRIBLE 
POSSIBLE 
FLEXIBLE 
ASSEMBLE 
OBSTACLE 
ENCIRCLE 
SCHEDULE 
MARITIME 
AIRDROME 
AIRPLANE 
JETPLANE 
MEDICINE 
DOCTRINE 
POSTPONE 
SEABORNE 
AIRBORNE 
DEVELOPE 


ASSAULT 
INSTANT 
ELEMENT 
COMMENT 
CURRENT 
PRESENT 
APPOINT 
RECEIPT 
ATTEMPT 
SUPPORT 
SUGGEST 
HIGHEST 
NEAREST 
PROTEST 
REQUEST 
AGAINST 
OUTPOST 
PROVOST 
BOYCOTT 
WITHOUT 
LOOKOUT 
SIMPLEX 
TUESDAY 


ENVELOPE 
INSECURE 
PRESSURE 
DECREASE 
EXERCISE 
SURPRISE 
SUSPENSE 
DISPERSE 
TRAVERSE 
DEDICATE 
INDICATE 
INITIATE 
ESTIMATE 
ORDINATE 
DETONATE 
SEPARATE 
EVACUATE 
EXCAVATE 
OBSOLETE 
COMPLETE 
CONCRETE 
EXPEDITE 
DEFINITE 


RAILWAY 
SECRECY 
VACANCY 
SIGNIFY 
SATISFY 
RAPIDLY 
QUICKLY 
NIGHTLY 
SHORTLY 
COMPANY 
DESTROY 
PRIMARY 
SUMMARY 
LIBRARY 
JANUARY 
BRIBERY 
BATTERY 
INQUIRY 
CAVALRY 
VICTORY 
EMBASSY 
UTILITY 
SEVENTY 


OPPOSITE 
CONTINUE 
CRITIQUE 
THATHAVE 
DECISIVE 
POSITIVE 
PRESERVE 
EQUALIZE 
MOBILIZE 
INVADING 
DIVIDING 
BUILDING 
GUARDING 
ENGAGING 
DAMAGING 
MARCHING 
BREAKING 
FLANKING 
TOTALING 
SHELLING 
BATTLING 
SWIMMING 
TRAINING 


Table D-2 


PLANNING 
SWEEPING 
SHIPPING 
GROUPING 
ENTERING 
COVERING 
RETIRING 
ADVISING 
OPPOSING 
DRESSING 
PRESSING 
CROSSING 
DRIFTING 
FIGHTING 
SIGHTING 
LIMITING 
PAINTING 
PRINTING 
SPOTTING 
DELAYING 
RALLYING 
CARRYING 
FERRYING 
APPROACH 
ENTRENCH 
INTRENCH 
RESEARCH 
- DESPATCH 
DISPATCH 
SKIRMISH 
DIMINISH 


(25. List of words used in military text arranged alphabetically 


GONFIDENTIAL 


in reverse order according to word Length (U)--Continued 
EIGHT LETTER WORDS—Continued 


ELEVENTH 
ANTITANK 
CODEBOOK 
CHEMICAL 
CLERICAL 
TACTICAL 
CRITICAL 
NAUTICAL 
OFFICIAL 
MATERIAL 
MEMORIAL 
NATIONAL 
INTERNAL 
CORPORAL 
HOSPITAL 
APPROVAL 
MATERIEL 
PARALLEL 
SENTINEL 
SEALEVEL 
PROTOCOL 
MERCIFUL 
TELEGRAM 
AMERICAN 
EUROPEAN 
CIVILIAN 
HAVEBEEN 
NINETEEN 
EIGHTEEN 
THIRTEEN 
FOURTEEN 


CAMPAIGN 
CHAPLAIN 
MAINTAIN 
MOUNTAIN 
BULLETIN 
INVASION 
DECISION 
DIVISION 
LOCATION 
AVIATION 
CITATION 
TAXATION 
JUNCTION 
IGNITION 
POSITION 
FORENOON 
SQUADRON 
GARRISON 
NORTHERN 
SOUTHERN 
CIRCULAR 
DECEMBER 
REMEMBER 
NOVEMBER 
DEFENDER 
RECORDER 
ENGINEER 
TRANSFER 
DECIPHER 
ENCIPHER 


PRISONER 
IMPROPER 
REPEATER 
DESERTER 
DISASTER 
REGISTER 
CANISTER 
RECEIVER 
REVOLVER 
OBSERVER 
MANEUVER 
EMPLOYER 
HOWITZER 
CORRIDOR 
SUPERIOR 
INTERIOR 
EXTERIOR 
OPERATOR 
DICTATOR 
REJECTOR 
DIRECTOR 
DETECTOR 
ASSOONAS 
POLITICS 
COMMANDS 
ADVANCES 
BARRAGES 
MESSAGES 
REMEDIES 
SUPPLIES 


VEHICLES 
MISFIRES 
DEFENSES 
EXPENSES 
PURPOSES 
RESERVES 
ANALYSIS 
BARRACKS 
MISSIONS 
STATIONS 
FACTIONS 
PONTOONS 
WARSHIPS 
OFFICERS 
SOLDIERS 
CARRIERS 
TRAILERS 
TRAWLERS 
CRUISERS 
FIGHTERS 
QUARTERS 
CARELESS 
WIRELESS 
BUSINESS 
DARKNESS 
CONGRESS 
PROGRESS 
FORTRESS 
DISTRESS 


REDCROSS | 


NINE LETTER WORDS 


RESPECTS 
ELEMENTS 
ATTEMPTS 
PROTESTS 
OUTPOSTS 
ENORMOUS 
LUMINOUS 
RIGOROUS 
VIGOROUS 
CONTRACT 
INDIRECT 
CONFLICT 
DISTRICT 
INSTRUCT 
AIRCRAFT 
DAYLIGHT 
MIDNIGHT 
PROHIBIT 
SERGEANT 
DOMINANT 
ADJUTANT 
ADJACENT 
INCIDENT 
ARMAMENT 
MOVEMENT 
REGIMENT 
APPARENT 
PASSPORT 
INTEREST 
REENLIST 


WITHDRAW 
WITHDREW 


TOMORROW 


PARALLAX 
SATURDAY 
THURSDAY 
CAUSEWAY 
EFFICACY 
IDENTIFY 
STRATEGY 
PROBABLY 
ASSEMBLY 
ACTUALLY 
MONOPOLY 
EASTERLY 
WESTERLY 
BOUNDARY 
MILITARY 
SANITARY 
FEBRUARY 
CEMETERY 
ADVISORY 
INFANTRY 
CAPACITY 
FATALITY 
CALAMITY 
VICINITY 
PRIORITY 
ACTIVITY 
CASUALTY 


MEMORANDA 
STRATEGIC 
AUTOMATIC 
PATRIOTIC 
BALLISTIC 
BEACHHEAD 
SPEARHEAD 
DESCRIBED 
ANNOUNCED 
BLOCKADED 
SUCCEEDED 
PROCEEDED 
COMMANDED 
SUSPENDED 
BOMBARDED 
FORTIFIED 


CANCELLED 
COMPELLED 
DETRAINED 
ENTRAINED 


CONDEMNED 


ECHELONED 
DEVELOPED 


CONQUERED 


PREFERRED 
CONFERRED 
DECREASED 
INCREASED 
CONDENSED 
COLLAPSED 
DISPERSED 
ADDRESSED 


IMPRESSED 
DISCUSSED 
INDICATED 
POPULATED 
ESTIMATED 
DOMINATED 
DETONATED 
SUSPECTED 
CORRECTED 
PROTECTED 
INFLICTED 
COMPLETED 
INHABITED 
EXHIBITED 
ASSAULTED 
APPOINTED 


ATTEMPTED 
PROTESTED 
REQUESTED 
SUBMITTED 
CONTINUED 
DESTROYED 
MOTORIZED 
SEMIRIGID 
RECOMMEND 
REARGUARD 
NORTHWARD 
SOUTHWARD 
AMBULANCE 
DOMINANCE 
CLEARANCE 
ENDURANCE 


ASSURANCE 
ALLOWANCE 
INCIDENCE 
REFERENCE 
INFLUENCE 
REENFORCE 
REINFORCE 
LONGITUDE 
COMMITTEE 
ADVANTAGE 
CARTRIDGE 
CHALLENGE 
AVAILABLE 
UNTENABLE 
DIRIGIBLE 
PRINCIPLE 


AERODROME 
HURRICANE 
AEROPLANE 
INTERVENE 
FRONTLINE 
DETERMINE 
TELEPHONE 
INTERFERE 
ELSEWHERE 
SHELLFIRE 
THEREFORE 
PROCEDURE 
PREMATURE 
DEPARTURE 
NAVALBASE 
MANGANESE 


D-15 


D-16 


Table D-2 ae List of words used in military text arranged alphabetically 


CRITICISE 
INTERPOSE 
ASSOCIATE 
IMMEDIATE 
OSCILLATE 
CIRCULATE 
DESIGNATE 
ALTERNATE 
COOPERATE 
ELABORATE 
PENETRATE 
REINSTATE 
CIGARETTE 
PARACHUTE 
DESTITUTE 
TECHNIQUE 
EXPANSIVE 
DEFENSIVE 
OFFENSIVE 
EXPENSIVE 
INTENSIVE 
EXTENSIVE 
EXPLOSIVE 
EXCESSIVE 
INCLUSIVE 
EXCLUSIVE 
TENTATIVE 
DEFECTIVE 
EFFECTIVE . 
OBJECTIVE 
INCENTIVE 
EXECUTIVE 
RECOGNIZE 
SERVICING 
ADVANCING 
PRECEDING 
EXTENDING 


ATOMICBOMB 
GEOGRAPHIC 
GYROSCOPIC 
DIPLOMATIC 
BRIDGEHEAD 
PRESCRIBED: 
REENFORCED 
REINFORCED 
BEENNEEDED 
UNEXPENDED 


-GONFIDENTIAL— 


in reverse order according to word length (U)--Continued 
NINE LETTER WORDS-— Continued 


REGARDING PERSONNEL INVENTION CONTINUES STATEMENT 
ACCORDING CABLEGRAM PROMOTION BUILDINGS EQUIPMENT 
INCLUDING RADIOGRAM SEMICOLON OFFICIALS GROUPMENT 
LAUNCHING FIREALARM AFTERNOON REPRISALS INTERMENT 
ATTACKING — CRITICISM DISAPPEAR PROPOSALS ALLOTMENT 
DEBARKING MECHANISM IRREGULAR _ CIVILIANS PERMANENT 
REFILLING DIETITIAN SEPTEMBER CAMPAIGNS DIFFERENT 
SCREENING SEVENTEEN COMMANDER MAINTAINS REPRESENT 
REMAINING SUSPICION SURRENDER DIVISIONS RESTRAINT 
OBTAINING BATTALION REMAINDER MUNITIONS INTERCEPT 
INCLINING REBELLION PASSENGER POSITIONS INTERRUPT 
BEGINNING COLLISION MESSENGER ENGINEERS TRANSPORT 
RETURNING PROVISION BRIGADIER PRISONERS NORTHEAST 
PREPARING EXPANSION STRAGGLER READINESS SOUTHEAST 
NUMBERING ASCENSION NEWSPAPER CONFLICTS NORTHWEST 
CENTERING DIMENSION CHARACTER DISTRICTS SOUTHWEST 
REQUIRING EXTENSION KILOMETER INCIDENTS INTERVIEW 
OPERATING EXPLOSION BAROMETER MOVEMENTS YESTERDAY 
ENLISTING ADMISSION GYROMETER OUTSKIRTS WEDNESDAY 
RECEIVING EXCLUSION DESTROYER ANONYMOUS EMERGENCY 
REVIEWING RADIATION PROJECTOR APPARATUS NORTHERLY 
EMPLOYING VARIATION PROTECTOR . DISINFECT SERIOUSLY 
OCCUPYING INFLATION CHAUFFEUR INTERDICT INSTANTLY 
PARAGRAPH FORMATION LOGISTICS DIFFICULT ACCOMPANY 
ESTABLISH OPERATION STANDARDS COMBATANT ARBITRARY 
TWENTIETH SITUATION RESOURCES IMPORTANT NECESSARY 
FIFTEENTH ELEVATION COMPANIES ASSISTANT SECRETARY 
SIXTEENTH OBJECTION BATTERIES CONFIDENT ARTILLERY 
WATERTANK DIRECTION EMBASSIES PRESIDENT ACCESSORY 
TECHNICAL CONDITION AIRDROMES DEPENDENT TERRITORY 
CHRONICAL COALITION SEAPLANES NEGLIGENT LIABILITY 
PRACTICAL PARTITION AIRPLANES DEFICIENT HOSTILITY 
POLITICAL DETENTION = EXERCISES EFFICIENT PROXIMITY 
IDENTICAL RETENTION WITNESSES PLACEMENT INDEMNITY 
PRINCIPAL INTENTION ADDRESSES AGREEMENT INTEGRITY 
DISMISSAL ATTENTION ESTIMATES AMUSEMENT NECESSITY 
CONTINUAL 
TEN LETTER WORDS 
APPROACHED COMPRESSED UNDERSTOOD CONFIDENCE 
ENTRENCHED DISTRESSED COASTGUARD NEGLIGENCE 
DESPATCHED DESIGNATED POSTOFFICE EXPERIENCE 
DISPATCHED RESTRICTED ACCORDANCE PREFERENCE 
THREATENED INSTRUCTED ALLEGIANCE DIFFERENCE 
MAINTAINED PROHIBITED APPEARANCE CONFERENCE 
DETERMINED REENLISTED ACCEPTANCE CAMOUFLAGE 
ONEHUNDRED MECHANIZED RESISTANCE DEPENDABLE 
DECIPHERED CONTRABAND ~— ASSISTANCE EXPENDABLE 
ENCIPHERED UNDERSTAND PRECEDENCE IMPASSABLE 


Table D=-2 (of, List of words used in military text arranged alphabetically 
‘in reverse order according to word length (U)-=Continued 


UNSUITABLE EVACUATING ALLOCATION GONIOMETER CONTINGENT 
ACCEPTABLE COLLECTING FOUNDATION HYDROMETER = SUFFICIENT 
IMPOSSIBLE CONNECTING RECREATION HYGROMETER CONVENIENT 
ASPOSSIBLE INFLICTING . IRRIGATION AMBASSADOR EQUIVALENT 
RECEPTACLE EXPEDITING NAVIGATION INSTRUCTOR ENGAGEMENT 
MOTORCYCLE RECRUITING REGULATION BALLISTICS MANAGEMENT 
AUTOMOBILE ATTEMPTING POPULATION STATISTICS EXCITEMENT 
DISCIPLINE SUPPORTING ESTIMATION CROSSROADS DETACHMENT 
QUARANTINE EXTINGUISH DOMINATION DESPATCHES ATTACHMENT 
ENTERPRISE NINETEENTH DETONATION SISPATCHES EXPERIMENT 
TRANSVERSE EIGHTEENTH OCCUPATION ASSEMBLIES ENROLLMENT 
COORDINATE THIRTEENTH SEPARATION FACILITIES ASSIGNMENT 
ILLUMINATE FOURTEENTH DECORATION ACTIVITIES ATTAINMENT 
ANTICIPATE WILLATTACK LIMITATION CASUALTIES INTERNMENT 
ILLITERATE ARTIFICIAL SANITATION FRONTLINES GOVERNMENT 
ILLUSTRATE CREDENTIAL INVITATION SUBMARINES ASSESSMENT 
COMPENSATE ADDITIONAL EVACUATION OBJECTIVES COMMITMENT 
DISTRIBUTE ACCIDENTAL EVALUATION ENEMYTANKS DEPARTMENT 
SUBSTITUTE REGIMENTAL EXCAVATION SUSPICIONS ENLISTMENT 
CONSTITUTE INDIVIDUAL COLLECTION COLLISIONS INSTRUMENT 
COMMUNIQUE WITHDRAWAL CONNECTION PROVISIONS DEPLOYMENT 
TWENTYFIVE AIRCONTROL INSPECTION EXPLOSIONS EMPLOYMENT 
SUCCESSIVE SUCCESSFUL CORRECTION FORMATIONS PERSISTENT 
IMPRESSIVE RESPECTFUL PROTECTION OPERATIONS AIRSUPPORT 
LOCOMOTIVE MEMORANDUM — EXHIBITION DIRECTIONS CONSPIRACY 
CENTRALIZE SUSPENSION EXPEDITION CONDITIONS DEFICIENCY 
NATURALIZE DISPERSION DEFINITION TROOPSHIPS EFFICIENCY 
DEMOBILIZE CONCESSION AMMUNITION NEWSPAPERS COMPLETELY 
COMMANDING CONFESSION" OPPOSITION KILOMETERS APPARENTLY 
DEBOUCHING DEPRESSION PROPORTION DESTROYERS INCENDIARY 
DETRUCKING IMPRESSION REVOLUTION TRANSPORTS COMMISSARY 
ENTRUCKING POSSESSION MACHINEGUN SUSPICIOUS ELEMENTARY 
ENCIRCLING SUBMISSION BATTLESHIP VICTORIOUS LABORATORY 
SIGNALLING COMMISSION CENSORSHIP CIRCUITOUS TRAJECTORY 
PATROLLING PERMISSION ARMOREDCAR CONTINUOUS CAPABILITY 
OVERCOMING DISCUSSION DIVEBOMBER PHOSPHORUS AUDIBILITY 
DETRAINING CONCLUSION COMMANDEER ~~ FLASHLIGHT VISIBILITY 
CONCERNING DEDICATION DISPATCHER COMMANDANT _ SIMILARITY 
INDICATING INDICATION MILLIMETER LIEUTENANT INSECURITY 
ANTEDATING 

ELEVEN LETTER WORDS 
IMPEDIMENTA SURRENDERED CONSTITUTED CATASTROPHE CUSTOMHOUSE 
TOPOGRAPHIC ENCOUNTERED BATTLEFIELD IMFLAMMABLE CERTIFICATE 
RECOMMENDED TRANSFERRED PERFORMANCE RESPONSIBLE COMMUNICATE 
PREARRANGED DISINFECTED MAINTENANCE NAVALBATTLE INVESTIGATE 
ESTABLISHED REAPPOINTED COINCIDENCE TEMPERATURE APPROPRIATE 
OVERWHELMED INTERCEPTED SUBSISTENCE MANUFACTURE APPROXIMATE 
DISAPPEARED INTERRUPTED ACKNOWLEDGE SCHOOLHOUSE EXTERMINATE 


TEN LETTER WORDS— Continued 


D-17 


CONFIDENTIAL — 


Table D-2 (ey, List of words used in military text arranged alphabetically 


in reverse order according to word length (U)--Continued 
ELEVEN LETTER WORDS- Continued 


DETERIORATE 
CONCENTRATE 
DEMONSTRATE 
NECESSITATE 
DISCONTINUE 
SEVENTYFIVE 
PROGRESSIVE 
RETROACTIVE 
DESCRIPTIVE 
SYNCHRONIZE 
APPROACHING 
INTERVENING 
ENGINEERING 
INTERFERING 
ALTERNATING 
INTERESTING 
WITHDRAWING 
DISTINGUISH 
SEVENTEENTH 
NAVALATTACK 
STRATEGICAL 
TRADITIONAL 
CONTINENTAL 
FIRECONTROL 


TRANSPACIFIC 
HYDROGRAPHIC 
UNIDENTIFIED 
COMMISSIONED 
DISSEMINATED 
CONCENTRATED 
DEMONSTRATED 
DISORGANIZED 
SIGNIFICANCE 
INTELLIGENCE 
INTERFERENCE 
INCOMPETENCE 
CONSIDERABLE 
FIGHTERPLANE 
INTERMEDIATE 
DECENTRALIZE 
GENERALSTAFF 
TRANSFERRING 
ENTERPRISING 
ILLUMINATING 
DISTRIBUTING 


D-18 


NATIONALISM RESTRICTION ENEMYPLANES CONFINEMENT 
SMOKESCREEN _ DISTINCTION PHILIPPINES REQUIREMENT 
APPLICATION DESTRUCTION PARENTHESES MEASUREMENT 
ASSOCIATION INSTRUCTION HEAVYLOSSES IMPROVEMENT 
RETALIATION RECOGNITION COMMUNIQUES CONCEALMENT 
DEBARKATION REQUISITION PARENTHESIS ECHELONMENT 
EMBARKATION COMPOSITION CREDENTIALS DEVELOPMENT 
LEGISLATION DISPOSITION BATTLESHIPS APPOINTMENT 
CIRCULATION COMPETITION ARMOREDCARS COMPARTMENT 
INFORMATION DESCRIPTION CORRECTNESS BELLIGERENT 
EXPLANATION CONSUMPTION ENGAGEMENTS INCOMPETENT 
DESIGNATION INSTITUTION ASSIGNMENTS FINGERPRINT 
RESIGNATION LIGHTBOMBER ASSESSMENTS DISCREPANCY 
EXAMINATION HEAVYBOMBER INSTRUMENTS PHOTOGRAPHY 
PREPARATION RANGEFINDER  ESTIMATEDAT IMMEDIATELY 
COOPERATION DYNAMOMETER SIGNIFICANT EXTENSIVELY 
IMMIGRATION THERMOMETER INDEPENDENT ~~ EFFECTIVELY 
INSPIRATION INTERPRETER INTELLIGENT PRELIMINARY 
CORPORATION RECONNOITER COEFFICIENT CONTROVERSY 
PENETRATION BLOCKBUSTER BOMBARDMENT ELECTRICITY 
ARBITRATION AERONAUTICS REPLACEMENT NATIONALITY 
COMPUTATION NAVALFORCES EMPLACEMENT SUITABILITY 
OBSERVATION ACCESSORIES ENFORCEMENT SUPERIORITY 
RESERVATION — HOSTILITIES ARRANGEMENT . 
TWELVE LETTER WORDS 
CONSTITUTING ILLUMINATION SUBSTITUTION REPLACEMENTS 
BREAKTHROUGH = ANTICIPATION CONSTITUTION EMPLACEMENTS 
GEOGRAPHICAL REGISTRATION NORTHWESTERN MEASUREMENTS 
CONFIDENTIAL ILLUSTRATION SOUTHWESTERN ADVANTAGEOUS 
PRESIDENTIAL INAUGURATION MARKSMANSHIP SIMULTANEOUS 
RECREATIONAL COMPENSATION MEDIUMBOMBER = ANTIAIRCRAFT 
AGRICULTURAL CONVERSATION COMMISSIONER NONCOMBATANT 
DEPARTMENTAL RADIOSTATION PSYCHROMETER CONVALESCENT 
UNSUCCESSFUL CONTINUATION SHARPSHOOTER DISPLACEMENT 
GENERALALARM — PRESERVATION DIFFICULTIES COMMENCEMENT 
VETERINARIAN MOBILIZATION UNITEDSTATES ANNOUNCEMENT |. 
TRANSMISSION ORGANIZATION PREPARATIONS ENTANGLEMENT 
VERIFICATION INTERDICTION OBSTRUCTIONS DECIPHERMENT 
CONFISCATION ROADJUNCTION INSTRUCTIONS ENCIPHERMENT 
COMMENDATION INTRODUCTION LIGHTBOMBERS REENLISTMENT 
CONCILIATION CONSTRUCTION HEAVYBOMBERS INEFFICIENCY 
CANCELLATION INTERVENTION HEADQUARTERS SUCCESSFULLY 
PROCLAMATION INTERCEPTION PREPAREDNESS RESPECTFULLY 
CONFIRMATION CONSCRIPTION COMPLETENESS SATISFACTORY 
CONFORMATION INTERRUPTION CARELESSNESS INTRODUCTORY 
COORDINATION DISTRIBUTION SEARCHLIGHTS IRREGULARITY 


TRANSATLANTIC 
DISTINGUISHED 
DECENTRALIZED 
DISAPPEARANCE 
IMPRACTICABLE 
INDETERMINATE 
CORRESPONDING 
CONCENTRATING 
COUNTERATTACK 


CONFIDENTIAL 


Table D-2 es. List of words used in military text arranged alphabetically 
in reverse order according to 


CHRONOLOGICAL 
CONGRESSIONAL 
INTERNATIONAL 
SPECIFICATION 
QUALIFICATION 
COMMUNICATION 
ACCOMMODATION 
INVESTIGATION 
DISSEMINATION 


DETERMINATION 
EXTERMINATION 
CONSIDERATION 
CONCENTRATION 
DEMONSTRATION 
QUARTERMASTER 
CIRCUMSTANCES 
DISCREPANCIES 
PRELIMINARIES 


word length (U)--Continued 
THIRTEEN LETTER WORDS 


FIGHTERPLANES 
INSTALLATIONS 
MEDIUMBOMBERS 
MISCELLANEOUS 
INSTANTANEOUS 
REENFORCEMENT 
REINFORCEMENT 
REIMBURSEMENT 


FOURTEEN LETTER WORDS 


REINSTATEMENT 
ESTABLISHMENT 
ENTERTAINMENT 
REAPPOINTMENT 
APPROXIMATELY 
EXTRAORDINARY 
REVOLUTIONARY 
DEPENDABILITY 


CHARACTERISTIC 
RECONNAISSANCE 
DISCONTINUANCE 

. CORRESPONDENCE 
ADMINISTRATIVE 
REPRESENTATIVE 
DISTINGUISHING 


RECONNOITERING 
METEOROLOGICAL 
CIRCUMSTANTIAL 
CLASSIFICATION 
IDENTIFICATION 
RECOMMENDATION 


ADMINISTRATION 
INTERPRETATION 
TRANSPORTATION 
CENTRALIZATION 
NATURALIZATION 
DEMOBILIZATION 


REORGANIZATION 
RECONSTRUCTION 
IRREGULARITIES 
INVESTIGATIONS 
SATISFACTORILY 
RESPONSIBILITY 


D-19 


—GONFIDENTIAL — 


Table D—3 (Z). List of words used in military text arranged alphabetically 


LIST 


a 
> 
nN 
w 
tm 
tt) 
AAAWUSAAZZAZAAZCCOARIY 
Zz 
ra) 


D-20 


according to word pattern (U) 


PATTERN AA 


BZeul>e 


sate lawn 


AABA AGR 
AABA K 
AABA CH 
AABA BR 
AABA MA 
AABA PLA 
AABA RU 
AABA L 
AABA E 
AABA MI 
AABA TE 
AABA "GLA 
AABA LO 
AABA PA 
AABA CHA 
AABA A 
AABAACB A 
AABAACBDEA A 
AABAB PROC 
AABB co 
AABB BA 
AABBAACAC B 
AABBCBC SU 
AABCA B 
AABCA A 
AABCA F 
AABCA CA 
AABCA A 
AABCA I 
AABCADEC Co 
AABCADEC A 
AABCADEFEA A 
AABCB SCR 
AABCB SU 
AABCB DI 
AABCB 0 


-CONFIDENFIAL_—. 


Table D-3 ef, List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


PATTERN AA— Continued 


MISCELLANEOUS PATTERNS 
EEME NT AABCB 
EEPE R AABCB 
EESE AABCB 
EEZE AABCB 
NNIN G AABCB 
NNIN G AABCB 
NNIN G AABCB 
OOKO UT AABCB 
RROR AABCBDEB 
RROR AABCC 
RROR AABCC 
SSES .AABCC 
SSES AABCCB 
SSES AABCCDD 
SSIS AABCCDEFBC 
SSIS T AABCDA 
SSESSME NT AABCDA 
SSESSMENTS AABCDAB 
EEDED AABCDB 
FFEE AABCDB 
LLOO N AABCDB 
EENNEFDED AABCDB 
CCEEDED AABCDB 
EETLE AABCDB 
NNOUN CE AABCDBA 
OOTHO LE AABCDBABD 
RRIER AABCDBC 
SSETS AABCDBD 
SSUES AABCDBEC 
MMITMENT AABCDC 
TTENTION AABCDD 
NNOUNCEMEN T AABCDD 
EENIN G AABCDDCA 
FFERE D AABCDDCD 
FFERE NT AABCDEB 
FFICL AL 


AABCDEB 


FFICI_ ENT 
LLEGE 
LLEGE 
LLETE D 
MMETE R 
OODED 
RRIFI_ C 
TTERE D 
FFERENCE 
CCESS 
CCESS ORY 
MMISS ARY 
LLATTA CK 
MMITTEE 
CCESSORIES 
LLEGAL 
TTEMPT 
TTEMPTE D 
FFENSE 
LLENGE 
LLISTI C 
RRESTE D 
SSENGE R 
TTERIE § 
RRENDER 
RRENDERED 
MMANDAN T 
FFENDED 
LLISTICS 
FFICAC Y 
DDRESS 
LLNESS 
DDRESSED 
DDRESSES 
MMUNIQU. E 
OOPSHIP 


D-21 


AABCDEB 
AABCDEBC 
AABCDEC 
AABCDECB 
AABCDED 
AABCDEDFC 
AABCDEE 
AABCDEFA 
AABCDEFA 
AABCDEFB 
AABCDEFBA 
AABCDEFC 
AABCDEFC 
AABCDEFD 
AABCDEFD 
AABCDEFDGA 
AABCDEFGA 
AABCDEFGABF 
AABCDEFGD 
AABCDEFGDAE 
AABCDEFGDE 


ow 
FOPAAPSrPHOPF POD 


"” 
zan Quan oF0n oa 


re] 
Pas 
aa 


BLOCKA 


CONFIDENTIAL — 


Table D-3 (¢). List of words used in military text arranged 
alphabetically according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS— Continued 


SSEMBLE 
OOPSHIPS 
MMANDIN G 
TTLEFIEL D 
MMANDED 
MMUNITION 
MMANDEE R 
EENLISTE D 
RREGULAR 
FFENSIVE 
SSEMBLIES 
LLOTMENT 
OOPERATE 
LLUSTRAT E 
SSIGNMEN_ T 
SSIGNMENTS 
OOPERATIO N 
EENLISTMENT 
TTLESHIPS 
OORDINATION 
PPOINTMENT 


CONFIDENTIAL— 


Table D-3 X. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


S 
enn 


a") 
r=) 
oe) 
TI rtm 


MISCELLANEOUS PATTERNS-— Continued 


OTO RIZED 
OVO ST 
PIP E 
POP ULATED 
RAR Y 
RDR OME 
RTR IDGE 
RYR UN 
SAS TER 
SES 

SIS. T 
SUS PEND 
SYS TEM 
TAT ION 
TAT OR 
TIT LE 
TIT UDE 
TIT UDE 
TOT AL 
TOT ALING 
UGU ST 
USU AL 
UTU RE 
VIV ED 
EBEE N 
SESS ION 
TATTOO 
ININ G 
ININ G 
ININ G 
ININ G 
ININ G 
ININ G 
ININ G 
ISIS 
THTH E 
TITI ON 
ANADA 
ANAMA 
ECEDE 
ELEME NT 
ELEME NTARY 
ELEVE N 
EMETE RY 
EVERE 
IBILL TY 
IBITL ON 


D-23 


ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACA 
ABACADA 
ABACADB 
ABACADBA 
ABACADC 
ABACADD 
ABACADDA 
ABACADEC 
ABACB 
ABACB 
ABACB 


| ABACB 


ABACB 

ABACB 
ABACBDEC 
ABACBDEC 
ABACBDEFGFAG 
ABACC 


ABACC 
ABACC 
ABACC 
ABACC 
ABACCA 
ABACCA 
ABACCA 
ABACCDACC 
ABACCDC 
ABACCDEFEA 
ABACDA 
ABACDA 
ABACDA 


D-24 


Q 
9 
= 
oo 


-Q Q : 
> => 
ZoBawyunADZzZzm WO <UO 


Zz 


CONFIDENTIAL— 


Table D-3 (ox List of words used in military text arranged alphabetically 
according to word pattern (U)-- Continued 


MISCELLANEOUS PATTERNS— Continued 


ICINI TY 
ILITI A 
ILITI ES 
IMINI SH 
IMITI NG 
INITI. AL 
[INITI ON 
IRIGI 
IRIGI D 
ISITI ON 
IVILI AN 
IVISI ON 
OCOMO 
ONOPO- LY 
OTOCO  L 
TITUT E 
UNUSUAL 
ISIBILI TY 
INITION 
ECEDENCE 
INITIATE 
ETENESS 
AVALATTA CK 


ACANC Y 


ATAST  ROPHE 
ETECT OR 


. ISITS 


MEMBE R 
ETENTION 
ETENTION 
NONCOMBATANT 
EBELL ION 
ECESS ARY 
ECESS ITY 
ELESS 

ELESS 
ARALLA X 
EPELLE D 
OMORRO W 
ELESSNESS 
ARALLEL 
ECESSITATE 
ALASKA 
ARABIA 
AVALBA SE 


ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACEA 
ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACDA 
ABACDAAC 
ABACDAACD 
ABACDAC 
ABACDAD 
ABACDAED 
ABACDAEEC 
ABACDB 
ABACDB 
ABACDB 
ABACDBA 
ABACDC 
ABACDC 
ABACDC 
ABACDCA 
ABACDCCA 
ABACDCCAD 
ABACDCEA 
ABACDCECFGHIE 
ABACDD 
ABACDD 
ABACDDEC 
ABACDEA 
ABACDEA 
ABACDEA 
ABACDEA 
ABACDEAD 
ABACDEAFGE 
ABACDEB 
ABACDEB 
ABACDEBFA 
ABACDEC 
ABACDEC 
ABACDEC 
ABACDECA 


a) 
AurAnDooDW 


=) 


3 
cre ANOS nZ BOunnvACnnA 


ECEIVE 
ECEMBE 
EFENSE 
EJECTE 
ELEASE 
ELECTE 
EMEDIE 
EMERGE NCY 
ENEMIES 
EPEATE D 
EVENUE 
NKNOWN 
OMOTIO N 
EVENTEEN 
EVENTEENT H 
ESERTER 
EFENSES 
AVAILABLE 
AVALBATTLE 
ATALIT Y 
NONYMO US 
OLONEL 
EREFORE 
ECEIVI NG 
EVENIN G 
MOMETE R 
[MITATI ON 
NINETEEN 
NINETEENT H 
TATEMENT 
ETEOROLOGICAL 
FIFTEE N 
RTRESS 
FIFTEENT H 
ELEVATE 
EVELOPE 
IFICATI ON 
IMILARI TY 
SUSPENSE 
SUSPENSION 
ANATION 
OPOGRAP  HIC 
ECEPTACLE 
ABANDON 
AMAGING 
ARANTIN. E 
ENETRATE 


250 0 DW 


ABACDECFBA 
ABACDECFGB 
ABACDED 
ABACDED 
ABACDED | 
ABACDEDEDC 
ABACDEDFBA 
ABACDEDFGA 
ABACDEFA 
ABACDEFA 
ABACDEFA 
ABACDEFA 
ABACDEFA 
ABACDEFA 
ABACDEFAF 
_.ABACDEFB 
ABACDEFB 
ABACDEFC 
ABACDEFCDFE 
ABACDEFCFD 
ABACDEFD 
ABACDEFDF 
ABACDEFE 
ABACDEFGA 
ABACDEFGB 
ABACDEFGBA 
ABACDEFGBA 
ABACDEFGBEHF 
ABACDEFGDHH 
ABACDEFGE 
ABACDEFGHA 
ABACDEFGHIA 
ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 


QO Zowo 


wher Lone) 


iplwk7,) 


Table D-3 eS. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS— Continued 


ETERIORATE 
ENETRATION 
APABILI TY 
OTORCYC LE 
SUSPICI ON 
ENERALALAR M 
SUSPICIOUS 
SUSPICIONS 
EFECTIVE 
EFENSIVE 
ELEPHONE 
ETERMINE 
EVELOPME NT 
EXERCISE 
EXERCISES 
DEDICATE 
ENEMYTAN KS 
DEDICATI ON 
ETERINARIAN 
ELECTRICIT Y 
SUSPECTE D 
SUSPENDED 
ANALYSIS 
EXECUTIVE 
POPULATIO N 
ENEMYPLANE S 
EVENTYFIVE 
ETERMINATION 
ENERALSTAFF 
MEMORANDA 
MEMORANDUM 
ECENTRALIZE 
AFFA IR 

APPA 
APPA 
ARRA 
ARRA GE 
ARRA 
ASSA 
ASSA GE 
ASSA 
ATTA CH 
ATTA CK 
ATTA IN 
ATTA 
DEED 
EFFE CT 


ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 

ABBA 
ABBAB 
ABBAB 
ABBACA 
ABBACA 
ABBACB 
ABBACDA 
ABBACDA 
ABBACDB 
ABBACDEA 
ABBACDEDA 
ABBACDEFA 
ABBACDEFA 
ABBACDEFA 
ABBACDEFCD 
ABBACDEFDB 
ABBACDEFEC 
ABBACDEFGB 
ABBCA 


OT 


Bann imivlelwlelole) 
c 
sy 


ESSENGE R 
EFFECTE D 
ISSIONS 
IRRIGATI ON 
OPPOSITION 
EFFECTIVE 
IFFICULTI ES 
IMMIGRATI ON 
ILLITERATE 
ATTAINMENT 
ARRANGEMEN T 
ATTACHMENT 
ANNUAL 


D-25 


Table D-3 (% List of words used in military text arranged alphabetically © 


D-26 


ABBCA 
ABBCA 
ABBCA C 
ABBCA S 
ABBCA 
ABBCA 
ABBCA 
ABBCA 
ABBCA S 
ABBCADAEFC 
ABBCADAEFC 
ABBCADC 
ABBCBBDA P 
ABBCBDA 
ABBCBDAED 
ABBCCDAB 
ABBCDA 
ABBCDA 
ABBCDA 
ABBCDA 
ABBCDA 
ABBCDA 
ABBCDAB 
ABBCDAB 
ABBCDAEA 
ABBCDAEFC 
ABBCDAEFC 
ABBCDAEFGAE 
ABBCDAEFGAHE 
ABBCDAEFGAHE D 
ABBCDBCEA 

ABBCDCA 

ABBCDCA Cc 
ABBCDCAED 
ABBCDCAED Cc 
ABBCDCEFA 
ABBCDDCA Cc 
ABBCDDCA Cc 
ABBCDDCEAFGC 
ABBCDEA 
ABBCDEA 
ABBCDEA 
ABBCDEA 
ABBCDEA T 
ABBCDEAFB 
ABBCDEAFB 
ABBCDEAFBC 


wok = 


according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS— Continued 


APPEA 
APPEA 
ARRIA 
ETTLE 
ISSUI 
TEENT H 
TEENT H 
UFFEU R 
URROU ND 
APPEARANCE 
APPEARANCE 
APPEARE OD 
OSSESSIO N 
ASSISTA NCE 
ASSISTANT 
ASSOONAS 
ALLOWA NCE 
APPROA CH 
ARRIVA L 
ASSURA NCE 
ESSAGE 
ILLUMI 
ESSAGES 
ORRIDOR 
ELLIGERE NT 
ALLOCATIO N 
IMMEDIATE 
ILLUMINATIN G 
ILLUMINATION 
ISSEMINATION 
APPROPRIA TE 
EFFICIE NT 
OLLISIO N 
EFFICIENC Y 
OLLISIONS 
ADDITIONA L 
OMMISSIO N 
OMMISSIO. NER 
ACCOMMODATIO N 
ACCOMPA NY 
APPROVA =L 
ASSOCIA TE 
ELLFIRE 

ERRIBLE 
ACCORDANCE 
REENFORCE 
ACCEPT ANCE 


NATE 


ABBCDEAFBGBC 
ABBCDEAFD 
ABBCDEAFEC 
ABBCDEAFGC 
ABBCDEAFGC 
ABBCDEAFGHF 
ABBCDEFGA 
ABBCDEFGA 
ABBCDEFGA 
ABBCDEFGBA 
ABBCDEFGBAHAC 
ABBCDEFGEA 
ABBCDEFGHAD 
ABCA 

ABCA 

ABCA 

ABCA 

ABCA 

ABCA 


LIGHT 


REENFORCEMEN T 
APPLICATI ON 
ASSOCIATIO N 
ACCEPTABLE 
ALLEGIANCE 
ORRESPONDIN G 
ACCIDENTAL 
APPROXIMA TE 
OCCUPATIO N 
IRREGULARI TY 
IRREGULARITIE S 
ILLUSTRATI ON 
OMMENDATION 
ACKA GE 

ACUA TING 
ACUA TION 


468-095 O - 72 -19 


CONFIDENTIAL —— 


Table D-3 6ef. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued PP 


MISCELLANEOUS PATTERNS— Continued 


CHEC K 
CIRC | LE 
CIRC ULATE 
CONC EAL 
CONC LUDE 
DRED 
EADE 
EAGE 
EAGE 
EAME 
EAME 
EARE 
EASE 
EASE 
EASE 
EAVE 
ECHE LON 
D 
D 


RALZAADA 


ECKE 
ECTE 
EDGE 
EIZE 
ELIE 


mitt 

AQ 
| 

ne 


ies) 

6 

les] 
689347 72i 


ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 


FOR 
W 


EXPL 


RAPHIC 


W~ 
Z fe} Be eel ak af ae 
es] 0 ye) re 


D-27 


D-28 


Table D-3 


ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCA 
ABCAA 
ABCAA 
ABCAA 
ABCAA 
ABCAA 
ABCAAB 
ABCAAB 
ABCAACDEB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 


PRO 


Ey weUwvvowy Uun 


g 
wANWEAM 


~GONFIDENTIAL—_— 


List of words used in military text arranged alphabetically 


according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS- Continued 


RDER 
RDER 5 
REAR 
RECR 
RIER 
RIOR 


UIT 


ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCAB 
ABCABA 
ABCABB 
ABCABB 
ABCABC 
ABCABCA 
ABCABDA 
ABCABDB 
ABCABDBEFGFHIB 
ABCABDBEFGFHIED 
ABCABDC 
ABCABDED 
ABCABDEFA 
ABCABDEFGHD 
ABCAC 
ABCAC 
ABCAC 
ABCAC 
ABCAC 
ABCACA 
ABCACB 
ABCACBDEC 
ABCACDEFD 
ABCADA 
ABCADA 
ABCADA 
ABCADA 
ABCADA 
ABCADAB 
ABCADAC 
ABCADAC 
ABCADAEC 
ABCADAEFB 
ABCADAEFC 
ABCADAEFCE 
ABCADAEFGHF 


PA 
PR 


INTIN G 

INTIN G 

NTENT 

ONTON 

ORPOR AL 
RECRE ATION 
RIORI TY 
RIORI TY 
SEASE 

TECTE D 
TESTE D 
UTPUT 

ERFERE 

ISMISS 

ISMISS = AL 
THATHA VE 
ENTENTE 
ENTENCE 
REPRESE NT 
REPRESENTATIVE 


REPRESENTATIONS 
RETREAT 
ANGANESE 
ORPORATIO N 
RECREATIONA L 
ARMAM_~ ENT 
EARER 

PROPO SE 


P RAIRI E 


nOAWAR 


nn 


TESTS 
[ETITI 
RDERED 
PROPORTIO N 
PROPOSALS 
ALMANA C 
ELIEVE 
ENTERE D 
ESIEGE D 
EVIEWE D 
NTINENT 
EALEVEL 
INDIVID 
IGNITION 
TENTATIVE 
IGNIFICAN T 
IGNIFICANC E 
SUBSISTENCE 


AN 


AL 
UAL 


CONFIDENTIAL — 


Table D-3 (€). List of words used in military text arranged alphabetically 
according to word pattern (U)-~Continued 


MISCELLANEOUS PATTERNS— Continued 


ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADB 
ABCADBA 
ABCADBC 


ABCADBCEFCGG 


ABCADBD 
ABCADBEFD 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADC 
ABCADCA 
ABCADCB 
ABCADCB 


ABCADCEFBGABC 


‘ABCADCEFGED 


ABCADCEFGEHC 
ABCADCEFGEHBC 


ABCADD 
ABCADD 
ABCADD 
ABCADD 
ABCADD 
ABCADDA 
ABCADDA 
ABCADDECCFA 
ABCADDEFA 
ABCADEA 
ABCADEA 
ABCADEA 
ABCADEA 
ABCADEA 
ABCADEA 


ATLANT 
BRIBER 
CIRCUI 
EDNESD 
ISTICS 
OSIONS 
PREPAR 
PROPER 
PROPER 
INSIGNI 
PREPARE 


' PREPAREDNESS 


PREPARA TION 
CIRCUITOU S 
ADIATI ON 
ANDARD 
ARIATI ON 
ASIATI = C 
AVIATI ON 
EVIEWI NG 
EXTENT 
NVENTE D 
TACTIC S 
TARTER 
ZIGZAG 
NVENIEN T 
NDENSED 
TACTICA L 
ENTERTAINMENT 
CONCENTRATE 
CONCENTRATIN G 
CONCENTRATION 
EPRESS ION 
EXCESS 

ISTILL 

OSTOFF ICE 
OYCOTT 
AMBASSA DOR 
EXPELLE D 
UNSUCCESSFU L 
EXCESSIVE 
ADVANTA GE 
ADVANTA GEQUS 
ECREASE 
EPTEMBE R 
EQUESTE D 
ISCIPLI NE 


ABCADEAB 


ABCADEAFA 
ABCADEAFGA 
ABCADEB 
ABCADEB 
ABCADEB 
ABCADEB 
ABCADEB 
ABCADEBCE 
ABCADEC 
ABCADEC 
ABCADEC 
ABCADECA 
ABCADECAFD 
ABCADECFC 
ABCADEDA 
ABCADEDAFB 
ABCADEDBD 
ABCADEDBDE 
ABCADEDC 
ABCADEDFGA 
ABCADEDFGDBC 
ABCADEDFGFB 


ABCADEE 
ABCADEEBFGHC 
ABCADEED 
ABCADEEFBC 
ABCADEEFGD 
ABCADEFA 
ABCADEFA 
ABCADEFA 
ABCADEFA 
ABCADEFAB 
ABCADEFAB 
ABCADEFABGADE 
ABCADEFAGB 
ABCADEFB 
ABCADEFBA 
ABCADEFC 
ABCADEFC 
ABCADEFC 
ABCADEFCGHB 
ABCADEFD 
ABCADEFD 


NTINGENT 
EXPENDED 
EXPENSES 
EXTENDED 
ELSEWHERE 
EXPERIENCE 
ENTERIN 
ENTERIN 
ESPECTS 
INCIDEN 
ISFIRES 
INCIDENCE 
ANDATED 
ECRETAR Y 
OSCOPIC 
REARGUAR D 
ISTINCTION 
CONCERNIN G 
NFINEMEN T 
INVITATION 
SUBSTITUT E 
SUBSTITUTI ON 
EUTENANT 
ENTERPRISE 
CONCILIATION 
ENTERPRISIN G 
ROGRESS 
CANCELLATION 
CANCELLE ‘D 
CONCESSION 
ROGRESSIVE 
ECHELONE D 
ENVELOPE 
EXPEDITE 
EXPERIME NT 
INDICATIN G 
ISTINGUIS 
ISTINGUISHING 
INDICATION 
ADVANCED 
RAORDINAR Y 


BOMBARDM ENT 


CIRCULAR 
NTENABLE 
RETROACTIVE 
ADVANCIN G 
EXTENDIN G 


D-29 


D-30 


CONFIDENTIAL ~~ 


Table D-3 (ey. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS-— Continued 


ABCADEFD EXTERIOR ABCBA AC TIVIT Y 
ABCADEFE CONCRETE ABCBAA USELESS 
ABCADEFE EXPEDITI NG ABCBAAB P REFERRE D 
ABCADEFE EXPEDITI ON ABCBAB DIVIDI NG 
ABCADEFE OBSOLETE ABCBAB AC TIVITI ES 
ABCADEFE G ONIOMETE R ABCBABDEB P REFERENCE 
ABCADEFE PURPOSES ABCBABDEB REFERENCE 
ABCADEFE RECRUITI NG ABCBADA MINIMUM 
ABCADEFEA C COMPOSITIO N ABCBADB P RESERVE 
ABCADEFGA EXPENSIVE ABCBADB RESERVE 
ABCADEFGA - EXTENSIVE ABCBADB REVERSE 
ABCADEFGAF ECHELONMEN T ABCBADBC RESERVES 
ABCADEFGB C ASUALTIES ABCBADEB SPE CIFICATI ON 
ABCADEFGB CIRCULATI ON ABCBCDBA REMEMBER 
ABCADEFGBC CONCLUSION ABCBDA DEFEND 
ABCADEFGC INDICATED ABCBDA DEPEND 
ABCADEFGC S TRATEGICA L ABCBDA MU NITION §S 
ABCADEFGD EXTENSION ABCBDA RESEAR CH 
ABCADEFGDC CONCEALMEN T ABCBDA STATES 
ABCADEFGE REPRISALS ABCBDA STATUS 
ABCADEFGF BOMBARDED ABCBDA IN TEREST 
ABCADEFGHAB C ONFORMATION ABCBDAB DEFENDE R 
ABCADEFGHCA EXTERMINATE ABCBDAB - E NGAGING 
ABCADEFGHCFIG EXTERMINATION ABCBDABA DEFENDED 
ABCADEFGHEIGCF REORGANIZATION ABCBDABD DEPENDENT 
ABCADEFGHH R ESPECTFULL Y ABCBDABDEA STATISTICS 
ABCADEFGHIAJF CIRCUMSTANCES ABCBDAEFGB DEPENDABLE 
ABCADEFGHIB RETROACTIVE ABCBDAEFGHG DEPENDABILI TY 
ABCADEFGHIE GEOGRAPHICAL | |ABCBDCBA PARAGRAP H 
ABCADEFGHIGBH CIRCUMSTANTIA L | |ABCBDDBA DEFERRED 
ABCBA COMP LETEL Y ABCBDEA E CONOMIC 
ABCBA AWKWA_ RD ABCBDEA DAMAGED 
ABCBA CAPAC ITY ABCBDEA POLITICAL 
ABCBA PA CIFIC ABCBDEAEC MANAGEMENT 
ABCBA SPA CIFIC ABCBDEBA DEFEATED 
ABCBA HIN DERED ABCBDEBA DESERTED 
ABCBA DIVID E ABCBDEBA RECEIVER 
ABCBA GARAGE ABCBDEBA REPEATER 
ABCBA C ITATI ON ABCBDEFA REJECTOR 
ABCBA LEVEL ABCBDEFA STATIONS 
ABCBA REFER ABCBDEFBA DEVELOPED 
ABCBA REFER . ABCBDEFGA R_ ESISTANCE 
ABCBA P RESER- VATION ABCBDEFGBA DETERMINED 
ABCBA RESER VATION ABCBDEFGHFA DISINFECTED 
ABCBA TAXAT ION ABCBDEFGHIJBA DECENTRALIZED 
ABCBA HOS TILIT Y ABCCA LITTL E 
ABCBA U_ TILIT Y ABCCA PASSP ORT 


Table D-3 (@¥. List of words used in military text arranged alphabetically 


ABCCA 
ABCCABDEC 
ABCCBADED 
ABCCBCA 
ABCCBDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDA 
ABCCDAA 
ABCCDAAEB 
ABCCDAAEBFF 
ABCCDAAEFD 
ABCCDAB 
ABCCDAEC 
ABCCDAED 
ABCCDAEFB 
ABCCDAEFB 
ABCCDAEF BC 
ABCCDAEFC 
ABCCDAEFDGG 
ABCCDEA 
ABCCDEA 
ABCCDEA 
ABCCDEA 
ABCCDEAB 
ABCCDEAD 
ABCCDEAD 
ABCCDEADCDE 
ABCCDEBFGHDA 
ABCCDEFA 
ABCCDEFA 
ABCCDEFAGHFBE 
ABCCDEFBGHDGAD 
ABCCDEFGA 
ABCCDEFGHAFG 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 


CONFIDENTIAL — 


according to word pattern (U)-~Continued 
MISCELLANEOUS PATTERNS- Continued 


S TREET 
C ROSSROADS 
MILLIMETE R 
BE GINNING 
INF LAMMABL E 
COLLEC T 
CORREC T 
T RIGGER 
RUBBER 
RUNNER 
SPOOLS 
SPOONS 
SUGGES T 
SUPPOSE 
TURRET 
SUCCESS 
SUCCESSFU 
SUCCESSFUL 
SUCCESSIVE 
RESSURE 
TERRITOR 
CORRECTE 
COLLECTIO 
CORRECTIO 
CONNECTION 
CONNECTIN 
CORRECTNESS 
GASSING 
GETTING © 
ST RAGGLER 
IN TERRUPT 
IN TERRUPTE D 
COMMENCE 
COMMERCE 
COMMENCEMENT 
DISSEMINATED 
COMMUNIC ATE 
SUPPLIES 
COMMUNICATION 
CORRESPONDENCE 
R EAPPOINTE D 
R EAPPOINTEMENT 


a] 
<r 


a Z2A2z0< 


S ABOTA GE 
R AILWA Y 
ANIMAL 
S ANITA RY 
M ARSHA L 


ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 


x 


3 
rA mazzmn 


axe 


wn 
QO 
AAAADIAN 


moO 4 
THO UDJORADD DOA 


EXT 


NTAL 


NT. 


D-31 


D-32 


ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDA 
ABCDAA 
ABCDAA 
ABCDAA 
ABCDAA 
ABCDAA 
ABCDAAD 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDAB 
ABCDABA 


ES 


-GONFIDENTIAL—— 


Table D-3 (0%. List of words used in military text arranged 
alphabetically according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS- Cont inued 


NTAIN 
NTAIN 
NTERN 
NTLIN 
NTREN 
ONTRO 
ORIZO 
OUTBO 
PROMP 
RECOR 
REPOR 
RETUR 
RIMAR 
RIVER 
ROGER 
RTHER 


CZs zwzram 
BORNE 


RTHER 
RTHER- LY 
SATIS FY 
SHIPS 


SHIPS 
THIRT 
THOUT 
TRACT 
TRACT 
TRUCT 
TRUCT 
TWENT 
UREAU 
WESTW 
EFUGEE 
ODEBOO 
SINESS 
STRESS 
STRESS 


ORENOON 


DECIDE 
DECODE 
EARHEA 
EDUCED 
ENTREN 
ERASER 
GEORGE 
POSTPO 
RETIRE 
TIMATI 
DECIDED 


(0) 
Y 


ARD 
K 


D 
CH 


NE 
ON 


ABCDABAB 
ABCDABC 
ABCDABC 
ABCDABCEFD 
ABCDABEFA 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDAC 
ABCDACB 
ABCDACDAEFGB 
ABCDACEFDAF 
ABCDAD 
ABCDAD 
ABCDAD 
ABCDADC 
ABCDADEDAFB 
ABCDADEFEAGC 
ABCDAEA 
ABCDAEA 
ABCDAEAB 
ABCDAEABD 
ABCDAEAE 
ABCDAEB 
ABCDAEB 
ABCDAEB 
ABCDAEB 
ABCDAEB 
ABCDAEB 
ABCDAEB 
ABCDAEBA 
ABCDAEBC 
ABCDAEBFBDC 
ABCDAEBFC 
ABCDAEC 
ABCDAEC 
ABCDAEC 
ABCDAECA 
ABCDAECAB 
ABCDAECB 
ABCDAECD 
ABCDAECE 
ABCDAECFD 


<= 


INS 


roe 


EX 


INCLININ G 
AINTAIN 
AINTAIN ED 
PHOSPHORUS 
ENTRENCHE D 
ANGUAG E 
ANYWAY 
ERNMEN T 
NSTANT 
NSTANT LY 
SPERSE 

TRICTI ON 
TRIOTI C 


‘NDEMNED 


NSTANTANEOUS 
COINCIDENCE 


MOVEME 
MUSEME 
RIGORO 

ANITATI 


NT 
NT 
US 
ON 


INSTITUTION 


- ANTIAIRCRAFT 


EXTREME . 
MAXIMUM 
ITABILIT Y 
TEDSTATES 
ENTHESES 
IGHTING 
IGHTING 
RAILROA 
REPORTE 
RETURNE 
TRACTOR 
TRUCTOR 
RECORDER 
TONATION 
NIDENTIFIED 
SATISFACT ORY 
AVERAGE 
ISTRICT 
OUTPOST 
TWENTIET H 
NTERNMENT 
ISTRICTS 
ABORATOR Y 
OUTPOSTS 
AMINATION 


900 


Table D=3 


—GONFIDENTIAL 


MISCELLANEOUS PATTERNS-— Continued 


(25. List of words used in Military text arranged alphabetically 
according to word pattern (U)--Continued 


ABCDAED T 
ABCDAEE 
ABCDAEE 

ABCD AEE 
ABCDAEEFAB 
ABCDAEFA 
ABCDAEFAB 
ABCDAEFB 
ABCDAEFBE 
ABCDAEFC 
ABCDAEFC 
ABCDAEFC 
ABCDAEFCA 
ABCDAEFCA 
ABCDAEFD 
ABCDAEFD 
ABCDAEFD 
ABCDAEFD 
ABCDAEFDB 
ABCDAEFDE 
ABCDAEFE 
ABCDAEFE 
ABCDAEFEGE 
ABCDAEFF 
ABCD AEFGAHB 
ABCDAEFGC 
ABCDAEFGD 
ABCDAEFGFE 
ABCDAEFGHC 
ABCDAEFGHFBC 
ABCDBA PR 
ABCDBA W 
ABCDBA DIV 
ABCDBA 

ABCDBA Ss 
ABCDBA R 
ABCDBA -) 
ABCDBAA 
ABCDBAAEDBC 
ABCDBAB 

ABCDBAD . 
ABCDBAEAD 
ABCDBAEBE 
ABCDBBA 

ABCDBBA 
ABCDBBDEA T 
ABCDBCAEB 


°o 
< 


vu 
POANDOOUAZON 


PAR 
RE 


TR 


RAVERSE 
ACTUALLY 
EXPRESS 
THIRTEEN 
THIRTEENTH 
ERWHELME 
INFLICTIN 
RESCRIBE 
NEHUNDRED 
ANUFACTU 
ESIDENTI 
ISTRIBUT 
ISTRIBUTI 
ISTRIBUTI 
LASHLIGH 
ONTROVER 
SCENSION 
WINDWARD 
RESTRICTE 
RESTRICTI 
ENTHESIS 
RETURNIN 
SPONSIBILI 
REDCROSS 
INSPIRATION 
REGARDING 
RESTRAINT 
ANSPACIFIC 


_ TWENTYFIVE 


CONSCRIPTION 
ACTICA L 
ATERTA NK 
EBOMBE R 
ENGINE 

ENTINE L 
EVOLVE 

ITUATI ON 
ENGINEE R 
ENGINEERING 
LIABILI TY 
TALIATI ON 
ISPOSITIO. N 
NEXPENDED 
ANTENNA 
ISCUSSI 
NSMISSION 
INTENTION 


ON 


ABCDBCEA 
ABCDBEA 
ABCDBEA 
ABCDBEA 
ABCDBEAB 
ABCDBEAE 
ABCDBEAFB 
ABCDBEAFCDB 
ABCDBEAFD 
ABCDBEAFD 
ABCDBECA 
ABCDBEFAGABC 
ABCDBEFAGEB 
ABCDBEFBA 
ABCDBEFCDAB 
ABCDBEFGA 
ABCDBEFGAB 
ABCDBEFGBCHIA 
ABCDBEFGHA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCA 
ABCDCAAC 
ABCDCAB 
ABCDCABCA 
ABCDCAC 
ABCDCAC 
ABCDCAD 
ABCDCAEAB 

| ABCDCAEB 
ABCDCAED 
ABCDCAED 

| ABCDCAEFD 

| ABCDCAEFDGHEGA 
‘ABCDCBABC 

| ABCDCBCEA 
|ABCDCEA 
|ABCDCEA 
|ABCDCEA 
|ABCDCEA 
ABCDCEA 
ABCDCEAFC 


PR 
FI 


ERODROME 
INCENDI ARY 
OTECTIO N 
TERCEPT 
TERCEPTE D 
ONTINUOU S 
INVENTION 
ARTERMASTER 
INCENTIVE 
INTENSIVE 
NCIRCLIN G 
ENTANGLEMENT 
TEMPERATURE 
DECREASED 
ONTINUATION 
YESTERDAY 
ARMOREDCAR 
DISTINGUISHED 
ERFORMANCE 
AIRCRAFT 
CRITIC 
CRITIC 
EFICIE 
ENGAGE 
OSITIO N 
OVISIO  N 
REALAR M 
PHILIPPI NES 
ANTITAN K 
NDEPENDEN T 
CRITICI SE 
CRITICI SM 
OPINION 
ENGAGEMENT 
OSITIONS 
EFICIENC Y 
OVISIONS 
CHARACTER 
CHARACTERISTIC 
TERPRETER 
STILITIES 
DGEHEAD 
EDICINE 
EFINITE 
EPARATE 
SURPRIS E 
ALIFICATI 


AL 
NT 


ON 


D-33 


ABCDCEAFE 
ABCDCEBA 
ABCDCECA 
ABCDCECDA 
ABCDCEFGAB 
ABCDCEFGCA 
ABCDCEFGCA 
ABCDDA 
ABCDDA 
ABCDDA 
ABCDDAB 
ABCDDAEACBE 
ABCDDAEF AF 
ABCDDAEFGHICE 
ABCDDEA 
ABCDDEA 
ABCDDEA 
ABCDDEAEC 
ABCDDECDFA 
ABCDDEFCGHA 
ABCDDEFEACGE 
ABCDDEFGGEDBA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA’ 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 


D-34 


[e) 
<r Zoow 


Q 
©) 
nm 


CONFIDENTIAL — 


Table D-3 (fs. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


ERSISTENT 
ELIGIBLE 
ESTITUTE 
NSTITUTIN G 
PHOTOGRAPH Y 
OBILIZATIO N 
OBILIZATIO N 
ECOMME ND 
OBACCO 
SHELLS 
EACHHEA D 
INEFFICIENC Y 
ECOMMENDED 
ECOMMENDATION 
DROPPED 
RSUPPOR T 
RTILLER Y 
COEFFICIE NT 
SCHOOLHOUS  E 


SCELLANEOUS 
CLASSIFICATIL ON 
ECONNAISSANCE 
AERONA UTICS 
AILHEA D 
AIRPLA NE 
AMBULA NCE 
ASTGUA RD 

' ATERIA-  L 
ATURDA Y 
AUSEWA Y 
AUTICA 
BLOCKB USTER 
CHANIC 
CHEMIC AL 
CONDUC T 
DISLOD GE 
DOWNED 
ECAUSE 
ECIPHE R 
ECLARE 
ECTIVE 
ECTURE 
EHICLE Ss 
ENCODE 
ENSATE 
ENTIRE 
EPLACE 


ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEA 
ABCDEAA 
ABCDEAAE 
ABCDEAAFED 
ABCDEAB 
ABCDEAB 


‘ ABCDEAB 


ABCDEAB 
ABCDEAB 
ABCDEAB 


MISCELLANEOUS PATTERNS— Continued 


OU 


EPULSE D 
ERABLE 
ERPOSE 
ERVICE 
EUROPE 
EUROPE AN 
EXCITE 
HROUGH 
IDENTI 
IDENTI FY 
INHABI 
IRECTI ON 
MEDIUM 
NCHRON [ZE 
NCTION 
NFIDEN T 
NOTHIN G 
NTRAIN 
OCATIO N 
OLUTIO N 
ORATIO N 
ORPEDO 
OVERCO M 
RAILER S$ 
RAWLER 
RECTOR 
REPAIR 
RTHWAR D 
RUISER 
SLANDS 
STRIPS 
SUNRISE 
TARGET 
THEAST 
THREAT 
THWEST 
TWELFT H 
UMINOU_ S 
EIGHTEE N 
SUBMISSI ON 
EIGHTEENTH 
INVADIN G 
LEXIBLE 
NATIONA L 
REQUIRE 
RESTORE D 
TSKIRTS 


Z 
os) 


ABCDEABA 
ABCDEABD 
ABCDEABE 
ABCDEABF 
ABCDEABFB 
ABCDEABFD 
ABCDEABFDC 
ABCDEABFE 
ABCDEABFFGHD 
ABCDEAC 
ABCDEAC 
ABCDEACFB 
ABCDEAD 
ABCDEAD 
ABCDEAD 
ABCDEADFD 
ABCDEAE 
ABCDEAE 
ABCDEAE 
ABCDEAE 
ABCDEAEFGC 
ABCDEAFA 
ABCDEAFAGE 
ABCDEAFAGHEAID 
ABCDEAFB 
ABCDEAFB 
ABCDEAFBC 
ABCDEAFC 
ABCDEAFC 
ABCDEAFC 
ABCDEAFD 
ABCDEAFE 
ABCDEAFE 
ABCDEAFE 
ABCDEAFF 
ABCDEAFGA 
ABCDEAFGAFB 
ABCDEAFGD 
ABCDEAFGE 
ABCDEAFGEE 
ABCDEBA 
ABCDEBA 
ABCDEBA 
ABCDEBA 
ABCDEBA 
ABCDEBA 
ABCDEBAB 


AT 


— 


A 


a< 


D ISPERSI 


—CONFIDENTIAL 


Table D-3 eS, List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS- Continued 


DEMANDED 
IMPEDIME NTA 
OMICBOMB 
REPAIRED 
REQUIREME NT 
NATIONALI SM 


NATIONALIT Y 
MARKSMANS _ HIP 
SHARPSHOOTER 
AUTOMAT _ IC 
RCONTRO- L 
ANTEDATIN G 
CONTACT 
ICTORIO 
RUISERS 
THREATENE D 
ENCODED 
ERMANEN-) T 
FORTIFI ED 
REQUIRI NG 
TRADITIONAL 
EPLACEME NT 
EXCITEMENT 
IDENTIFICATION 
CLERICAL 
INVASION 
RESOURCES 
IGNATION 
IGNATION 
NFIDENTI 
IMENSION 
ADJUTANT 
INTERIOR 
NFLUENCE 
EADINESS 
ECIPHERME NT 


US 


AL 


MEDIUMBOMBE R 
ON 


LEGISLATI 
MPARTMENT 
SMOKESCREE N 
DELAYED 
ETONATE 
INDEMNI TY 
ON 
RECOVER 
SURPLUS 
ARBITRAR Y 


ABCDEBAED 
ABCDEBFA 
ABCDEBFAGA 
ABCDEBFCAGBF 
ABCDEBFDGA 
ABCDEBFGAF 
ABCDEBFGHA 
ABCDEBFGHBCGIA 
ABCDECA 
ABCDECA 
ABCDECA 
ABCDECA 
ABCDECAB 
ABCDECAC 
ABCDECACFE 
ABCDECAFCDA 
ABCDECBA 
ABCDECBA 
ABCDECBA 
ABCDECBAFB 
ABCDECCFA 
ABCDECDCAFC 
ABCDECFA 
ABCDECFA 
ABCDECFBA 
ABCDECFEA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDA 
ABCDEDAB 
ABCDEDAC 
ABCDEDAFC 
ABCDEDFA 
ABCDEDFA 
ABCDEDFA 
ABCDEDFAC 
ABCDEDFAC 
ABCDEDFACDGB 
ABCDEDFCAB 
ABCDEDFCGAHB 
ABCDEDFDA 


ARBITRATI ON 
RIGADIER 
ENCOUNTERE D 
INTERNATIONA  L 
NAVIGATION 
EADQUARTER S 
ESPONSIBLE 
NATURALIZATION 


E NLISTIN G 


See 


el 


PRINCIP AL 
PRINCIP LE 
SKIRMIS H 
NTERMENT 
NTERVENE 
AINTENANCE 
TRANSATLANT _ IC 
NEGLIGENT 
REVOLVER 
ROTECTOR 
NEGLIGENCE 
DISCUSSED 
NTERFERENCE 
ENCIRCLE 
EVACUATE 
SEAPLANES 
STANDARDS 


_EWSPAPE 


R 
MARITIM E 
NTRABAN D 
OALITIO N 
ROMETER 
ROMETER 
ROMETER 
ROMETER 
ROMETER 
ONDITION 
OGNITION 
EWSPAPERS 
DICTATED 
EXCAVATE 
EXHIBITE D 
ANTICIPATE 
CLEARANCE 
ANTICIPATION 
INTERESTIN G 
INAUGURATION 
ARTIFICIAL 


D-35 


~CONFIDENTIAL— 


Table D-3 (7. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


ABCDEDFDEAB 
ABCDEDFDGHAIF 
ABCDEDFGA 
ABCDEDFGA 
ABCDEDFGABHED 
ABCDEDFGADB 
ABCDEDFGHAGD 


ABCDEDFGHAGDIE 


ABCDEEA 
ABCDEEA 
ABCDEEA 
ABCDEEACB 
ABCDEEAFDBC 
ABCDEEAFDBGD 
ABCDEEDFGBA 
ABCDEEDFGBAFE 
ABCDEEFAB 
ABCDEEFAB 
ABCDEEFAE 
ABCDEEFDGFA 
ABCDEEFGCAHB 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFA 


D-36 


MISCELLANEOUS PATTERNS-— Continued 


C ONSTITUTION 


CHRONOLOGICAL 
OCLAMATIO N 
RELIMINAR Y 
INDETERMINATE 
RELIMINARIE S 
ADMINISTRATIVE 
ADMINISTRATION 
ENROLLE D 
ERSONNE L 
IMPOSSI BLE 
IGNALLING 
INTELLIGENT 
INTELLIGENCE 
RECONNOITER 
RECONNOITERIN G 
ENROLLMEN T 
ONFESSION 
EMBASSIES 
DISAPPEARED 
INTERRUPTION 
ABLEGRA M 
AMERICA N 


C AMOUFLA GE 


FIGHT 


CHRONIC AL 


CONFLIC T 
CREPANC Y 
EABORNE 

EMPLOYE R 
ENCIPHE R 
ENFORCE 

ENLISTE D 


EPLOYME NT 
EQUIPME NT 
ERPLANE 
ESCORTE D 
ESCRIBE 
ETPLANE 
EXCLUDE 
INCLUSI VE 
LOGICAL 
ORMATIO N 
RANSFER 
REGULAR 
RISONER 
SAILORS 
SECTORS 


ABCDEFA 
ABCDEFA 
ABCDEFA 
ABCDEFAA 
ABCDEFAAF 
ABCDEFAAGC 
ABCDEFAB 
ABCDEFAB 
ABCDEFAB 
ABCDEFABA 
ABCDEFAC 
ABCDEFAC 
ABCDEFACB 
ABCDEFACD 
ABCDEFACGF 
ABCDEFAD 
ABCDEFAD 
ABCDEFAD 
ABCDEFAD 
ABCDEFAD 
ABCDEFAD 
ABCDEFADB 
ABCDEFADF 
ABCDEFAE 
ABCDEF AEGHEC 
ABCDEFAF 
ABCDEFAF 
ABCDEFAFCD 
ABCDEFAGA 
ABCDEFAGAB 
ABCDEFAGB 
ABCDEFAGB 
ABCDEFAGB 
ABCDEFAGB 
ABCDEFAGB 
ABCDEFAGBDB 
ABCDEFAGBHBD 
ABCDEFAGC 
ABCDEFAGCAHB 
ABCDEFAGE 
ABCDEFAGEC 
ABCDEFAGFD 
ABCDEFAGHAB 
ABCDEFAGHEBC 
ABCDEFAGHFD 
ABCDEFAGHFAIB 
ABCDEFAGHFAIBE 


DOHDDD 


SERIOUS LY 
STABLIS H 
TONIGHT 
EMPLOYEE 
RANSFERRE D 
RANSFERRIN G 
INCLUDIN G 
RADIOGRA M 
REMATURE 
EMPLACEME NT 
INTEGRIT Y 
RISONERS 
TRODUCTOR Y 
ALTERNATE 
ALTERNATIN G 
CONTRACT 
ESTROYER 
INTERVIE W 
OPERATOR 
RECONTRO L 
ROCEDURE 
ESTROYERS 
RANSVERSE 
ISCONTIN UE 
ISCONTINUANC E 
EXPANDED 
MPROVEME NT 
ADIOSTATIO  N 
ENCIPHERE D 
ENFORCEMEN T 
AEROPLANE 
ETACHMENT 
INFLATION 
REINFORCE 
TRAJECTOR Y 
REIMBURSEME = NT 
REINFORCEMEN T 


INTERDICT 
INTERDICTION 
EPARTMENT 
EPARTMENTA L 
REGISTRATI ON 


ENCIPHERMEN- T 
CONFISCATION 
INVESTIGATE 
INVESTIGATION 
INVESTIGATIONS 


Table D-3 


CONFIDENTIAL — 


>. List of words used in military text arranged alphabetically 
according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS— Continued 


ABCDEFAGHIF 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBA 
ABCDEFBAB 
ABCDEFBABGHD 
ABCDEFBGA 
ABCDEFBGBA 
ABCDEFCA 
ABCDEFCA 
ABCDEFCAB 
ABCDEFCAD 
ABCDEFCAGFC 
ABCDEFCBA 
ABCDEFCCFA 
ABCDEFCEA 
ABCDEFCGA 
ABCDEFDA 
ABCDEFDAB 
ABCDEFDBAB 
ABCDEFDBCAGB 
ABCDEFDEAB 
ABCDEFDGAB 
ABCDEFDGAHCD 
ABCDEFDGHA 
ABCDEFEA 
ABCDEFEAB 
ABCDEF EAGACE 
ABCDEFEAGDB 
ABCDEFECACD 
ABCDEFECAE 
ABCDEFEDCGCAHB 
ABCDEFEFA 
ABCDEFEGA 
ABCDEFEGA 
ABCDEFFA 
ABCDEFFA 
ABCDEFFAGE 
ABCDEF FEDAGBC 
ABCDEFFGAB 
ABCDEFGA 


REAKTHROUGH 
DECLARED 
DEPARTED 
DEPLOYED 
DEPORTED 
DETACHED 
EMPLOYME 
ENTRAINE 
REGISTER 
ROJECTOR 
MEASUREMENT 
MEASUREMENTS 
ENDURANCE 
DECIPHERED 
ESTIMATE 
NORTHERN 
ESTIMATES 
OMINATION 
ESTIMATEDAT 
DETONATED 
DISTRESSED 
DISPERSED 
ELABORATE 
EPARTURE 
USTOMHOUS E 
INTERVENING 
INTERVENTION 
INTERFERING 
ONSTRATION 
INTERMEDIATE 
HYDROGRAPH IC 
EINSTATE 
INGERPRIN T 
EINSTATEMENT 
CERTIFICATE 
THERMOMETER 
CONFERENCE 
INTERPRETATION 
OMPETITIO N 
EMOBILIZE 
OMPUTATIO N 
DERSTOOD 
IMPRESSI 
IMPRESSIVE 
INSTALLATIONS 
ONGRESSION AL 
DISARMED 


NT 
D 


ON 


ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGA 
ABCDEFGAB 
ABCDEFGAB 
ABCDEFGAB 
ABCDEFGABF 
ABCDEFGAC 
ABCDEFGAC 
ABCDEFGACB 
ABCDEFGAD 
ABCDEFGAD 
ABCDEFGADG 
ABCDEFGAEHBC 
ABCDEFGAFE 
ABCDEFGAG 
ABCDEFGAHB 
ABCDEFGAHCGIDE 
ABCDEFGBA 
ABCDEFGBA 
ABCDEFGBA 
ABCDEFGBA 
ABCDEFGBA 
ABCDEFGBACAHGD 
ABCDEFGBAE 
ABCDEFGBHA 
ABCDEFGBHIAKC 
ABCDEFGCAG 
ABCDEFGCHEA 


Adz 


DI 


co 


— 


ECHANIZE D 
ECHNIQUE 
ECOGNIZE 
ENFILADE 
EQUALIZE 
EQUIPAGE 
EQUIVALE 
ESIGNATE 
EXCHANGE 
GROUPING 
GUARDING 
INSECURI 
IPLOMATI 
NTRUCKIN 
NUMBERIN 
OBJECTIO 
OPERATIO 
SOLDIERS 
SPATCHES 
WITHDRAW 
WITHDREW 
ESPATCHES 
NDERST AND 
WITHDRAWI NG 
ENLISTMENT 
NSTRUMENT 
OUNDATION 
NSTRUMENTS 
SOUTHEAST 
SOUTHWEST 
SOUTHWESTE RN 
CONSTRUCTION 
IMPRACTICA BLE 
WITHDRAWAL 
INSPECTION 
RECONSTRUCTION 
DESCRIBED 
DESTROYED 
DETRAINED 
REMAINDER 
TRANSPORT 
TRANSPORTATION 
TRANSPORTS 
ESTABLISHE D 
ESTABLISHMENT 
CONFIDENCE 
RANGEFINDER 


D-37 


CONFIDENTIAL — 


Table D-3 (or List of words used in military text arranged alphabetically 


ABCDEFGDAHB 
ABCDEFGDAHBC 
ABCDEFGDBFHA 
ABCDEFGDHAIC 
ABCDEFGDHFAE 
ABCDEFGEA 
ABCDEFGEHA 
ABCDEFGFABF 
ABCDEFGFAG 
ABCDEFGGAG 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHA 
ABCDEFGHAB 
ABCDEFGHADB 
ABCDEFGHAGC 
ABCDEFGHBA 


D-38 


CE 


according to word pattern (U)--Continued 


MISCELLANEOUS PATTERNS-— Continued 


INSTRUCTION 
INSTRUCTIONS 
NTRALIZATION 
OBSTRUCTIONS 
ORGANIZATION 
EAVYBOMBE R 
ESCRIPTIVE 
NCOMPETENCE 
NCOMPETENT 
EAVYLOSSES 
CONSPIRAC Y 
DOMINATED 
ENTRALIZE 
EXCLUSIVE 
EXPANSIVE 
EXPLOSIVE 
MECHANISM 
ONSUMPTION 
INFORMATION 
CONVALESCENT 
DESIGNATED 


ABCDEFGHBA 
ABCDEFGHBIKA 
ABCDEFGHCAEB 
ABCDEFGHCAEB 
ABCDEFGHDAB 
ABCDEFGHDGCA 
ABCDEFGHDIKA 


ABCDEFGHIA 
ABCDEFGHIAB 
ABCDEFGHIAE 
ABCDEFGHIAF 
ABCDEFGHIDAB 
ABCDEFGHIFKA 
ABCDEFGHIGBA 
ABCDEFGHIJDA 


DESPATCHED 
DISORGANIZED 
INTRODUCTION 
ISCREPANCIES 
ONFIRMATION 
NORTHWESTERN 
REVOLUTIONAR Y 
COUNTERATTAC K 
EMONSTRATE 
AGRICULTURAL 
DISPATCHED 
OBSERVATIO N 
SUBMARINES 
ONVERSATION 
OMPENSATION 
OADJUNCTION 
ONSIDERATION 
SEARCHLIGHTS 
DEMONSTRATED 
SIMULTANEOUS 


-—G 
—P 


—-S 
—D 


co 
—S 


—T 
SI 


CONFIDENTIAL _ 


Table D—4 g. List of general digraphic idiomorphs (U) 


FO RC ED 


Ce 


-I 


-I 


—-A 
-C 


CA 


—I 


TR 


—F 


=) 


n ro 
BASS SERRA SAS Cam EaSOD SORE RAR SIZES EARS SAS | | 


CE 


US 


E— 


D-39 


CONFIDENTIAL 


Table D—4 . List of general digraphic idiomorphs (U) -Continued 


D-40 CONFIDENTIAL 


~CONFIDENTIAL 


Table D-5 g. List of playfair digraphic idiomorphs (U) 


SSCEREESEe 


—GONFIDENTIAL— | D-41 


D-42 


TR 


—B 


-S 


SI 
—-R 


—T 


BA 


-CGCONFIDENTIAL— 


Table D—5 —@. List of playfair digraphic idiomorphs (U) -Continued 


TI 


ON 


TE 


TH 


BA 


ON 


ON 


-CONFIDENTIAL 


Table D—5 g. List of playfair digraphic idiomorphs (U) —Continued 


-GONFIDENTIAL— Das 


468-095 O - 72 «20 


—GONFIDENTIAL— 


Table D—6 (). List of four—square digraphic idiomorphs (U) 


(Grouped by number of significant letters in the idiomorphic pattern) 


TWO LETTERS 
Ae Ax A> An Aw — Aq 
B LO CK| AD ED RE QU|ES T SA BO TA|GE 
I NV|AD ED RE QU|IR E SE VE RE 
D| AM AGE P|RI SO|NE R AC| TI VI TY 
CO MM| AN DS RE|SI ST |AN CE A| TT EN TION 
I SL} AN DS D IS PO|SI TI ON s| UC CE SS|FU LL Y 
A IR PL|AN ES PO|SI TI |ON 
E NE MY PL/ AN ES SO UT |H Pe 
DE SI GN| AT ED SQ UA \DR ON AR TI LL ER|Y 
E ST IM/AT ED FI GH|TE RP |LA NE AT TA CK ED 
I ND IC\AT ED MO|TO RI |ZE D R|EE NF OR CE 
C| AV AL| RY D EP AR|TU RE R|EE NF OR CE|ME NT 
N} AV AL UN US [UA L ID EN TI FY 
P RO|CE DU|RE IM PO SS IB|LE 
ME| CH AN/IZ ED Ac = Ae MO VE ME NT 
IM ME| DI AT/EL ¥ S|AB OT AG |E E|MP LA CE ME|NT 
WI TH| DR AW D ET|AC HM ENT PE RS ON NE|L 
WI TH| DR EW H| AS BE EN A| RT IL LE RY 
EM ER|GE NC ¥ BA TT AL|IO N 
L IE UT|EN ANIT BO MB ED Ae — — — A 
FI FT|EE N CA SU AL|TI ES CO MM UN IC ATjIO NS 
FI FT| CA SU AL |TY CO NC EN TR ATIE 
FI FT|Y CO MB AT RIEO RG AN IZ AT|IO N 
BR LD| GE HE} AD CO OR DI|NA TE S LI EU TE NA NT 
vj Ic IN|IT ¥ DI RE CT/10 N CO|NS TR UC TI ON 
Wi IT HD|RA W DI SP AT/CH 
A DD|IT I0/NA L ME] DI UM BO|MB ER {| Ae == == — — = 
A MM UN| IT IO|N DI VE BO!|MB ER CO MM IS SI ON ED 
CO ND| IT IO|N R OA| DJ UN CT IO N 
RE CO GN| IT IO|N RI EP LA CE|ME NT -B -B 
E| LE ME|NT R| ET RE AT UN AB LE 
MI LI|TA RY S| EV ER AL OB ST AC LE 
MI NI|MU M JU) NC TI ON AD VA NC E 
NI NT|H CO| NF IR MA|TI ON AG AI NS T 
P| OI NT I| NF OR MA|TI ON R AI LH EA D 
T| OM OR|RO W I] NT EL LI|GE NC E PR EP AR AT IO N 
PO NT| ON PA TR OL A SS AU LT 


CONFIDENTIAL — 


Table D-6 ds, List of four-square digraphic idiomorphs (U)--Continued 


TWO LETTERS ~Continued 
-B -B —R -B -B — —B 
B OM|BA RD CjOL ON CAIRR IE RS 
A IR|BO RNIE ClOL ON|EL MI|SS IO NS 
S EA|BO RNIE SU PE RI/OR ITIY TW EN TY 
A DV ANICI NG MIOT OR|IZ ED R EQIUE ST ED 
VI CI NI|TY OU TS/KI RT S 
DE TA! CH EQ UI|PM EN|T —}— — BR 
DE TA|CH ME NT A VE|RA GE IiDE NT IF IC}AT IO N 
H AV|EB EE|N B AR|RA GE MIEC HA NI ZEID 
M OV|EM EN|T _ AI|RC RA|FT DIEP LO YM EN|T 
EN EM/Y AN TI AI|RC RA|FT MIES SENG ER 
RIES ER! VE RE MA|IN DES TR OY ER} 
RIET URIN R EQ UI|RE MEINT A|IR SU PP ORIT 
FL ANIK M IS|SI NG VjIS IB IL IT|Y 
FO LL|OW PIER SOINN EL “E SS EN GER 
B AGIGA GE ES TI|MA TE/DA T I|MP AS SA BLIE 
HA SBIEE N P| LA TO] ON I/MP OS SI BLIE 
A PP RO AC/HI NG S UP|PL Y AINT IA IR CRIAF T 
DE BO UC|HI NG S UP|PO RT CIOM MA ND IN/G 
L AU NC/HI NG NA VA|LB AS E OP ER AT IOIN 
I MM EDIIA TE/LY F| OR WA! RD PR IS ON ER! 
IN IT|IA TE WI| ND WA| RD PR OC ED URIE 
F\IF TH RE EN FO RCIE 
TE RRIIT ORIY -R — —B TR AN SP OR/TA TI ON 
S|IX TY] | C\AS UA LT|Y YE ST ER DAY 
M IS CE|LL AN/EO US P|AT RO LS 
E|LE VA| TI ON B AT TL|ES HI PS 
E|LE VE|N GE NE RAIL BR — — =? 
LI AI|SO N W ILILA TT ACI|K R{EC OM ME ND ED] 
DA|MA GE T RAINS MI SS|IN N HE AV YL OS SE/S 
MO RNIIN G R EC\OG NI TIION R EC|OM ME ND AT LOIN 
U|NU SU} AL T RO|OP SH IP C]OM MU NI CA TION 
OB JE|CT IVE RE GI ME|NT R ECION NO IT ER INIG 


—GONFIDENTIAL— D-45 


CONFIDENTIAL — 


Table D-6 (g). List of four~square digraphic idiomorphs (U)--Continued 


THREE LETTERS 


oy oe ee = 


|RE QU ES TE|D B OM|BA RD ME{NT 


EL EM EN;|TS 
EN|GA GE MENT 


FOUR LETTERS 
AB A~ -B A- A- — -B -B —B_A~ AB 
H| EA DQ ua ER S |RE QU IR EM EN|T RE|PE AT ED| 
|= EV EN 
A~ —B AB ~B_A- A= -B 
AB -B A= u)gE NI NG |DE ST RO YE}R 
CA NC ra PiOS TP ONIE 
REICO NN AL!SS AN CE -B Aj -B — A- 
A- -B -B — A- |UN ID EN TI FI|ED 
AB -B — A- {RE CO NN OL TE(R 
AD VA NC ED -B A- — AB 
EN EM YT AN(KS A= -B — AB U|NS UC CE SSIFU L 
[IN TE RD IC|T 
(AB = BeBe . =B_A= — An —B 
|SI GH TI NGC| A- —B — A- -B |ME DI UM BO MBIER 
S|AT IS FA CT ORIY 
A= AB —B -B A-~ — —B A~ 
[AD DI TION AL A= — A- C- C- {VI SI BI LI Ty| 
{DI SP AT CH ES| 
A- AB — -B -B A- — — AB 
|SO UT HW ES|T A~ — — C- A~ C- |IN FO RM AT IOIN 
[RO AD JU NC TI ON| 
A- A= —B =B -B_A- — — A- -B 
W|/IT HD RA WA|L —B_AB A- [IN ST AL LA TI ON| 
DI SP|OS IT IO|N 
A= Am — A~ Ax P|OS IT LO|N SB a eB eed 
|CO MM AN DI NG| PR ES EN|T ICR OS SR OA DS! 
RE|PR ES EN|T 


CONFIDENTIAL 


Table D-6 ). List of four-square digraphic idiomorphs (U)--Continued 


FOUR LETTERS —Continued 


-B =D —D —B —B —— A- AB 
AI {RS UP PO RTI “|| F IG ATJER Pr, AN ES| 


—B ae es eB ee AR ROAR 
IN RU CT IO|N |] EIST AB LI SH ME NTI 
C\ON RU CT IOIN 


FIVE LETTERS 


Pie: Aes Re oo AB n ) -R =n 
TT ACIK ST RI BU TIION ST RU CT IN NS| 


-B AB A~ -B AB 
SA NCIE AC EM ENIT 


SIX LETTERS 


AB CB C~ A= Aces OR As ae: OB 
P|OS IT IO NSI| [In EN FI CA TI|ON 


AB —D —D AB : =-R AB AD —l 
C{ON DI TI ON Q UAIRT AIDM IN IS TRIAT IVE 
les DI OG RAIM 
An CB 
|sc HO 


Table D-6 (6). List of four-square digraphic idiomorphs (U)--Continued 


SEVEN LETTERS 


JR: AD oes, te DAD 
JRE EN FO RC EM ENIT 


EIGHT LETTERS 


AB -B AD — -B AD AB ~B C- AB CB AB -D C- AD C- =B 
[EM PL AC EM ENT |IN TE RD IC TI ON| 


}QU AR TE RM AS TE|R 


-GONFIDENTIAL—— D7 


CONFIDENTIAL — 


Table D—7 ). List of words containing like letters repeated at various intervals (U) 


AA(5)A 


PEESE SESE SSS SS 


BEEE 
as 
> 


> 
a 
4 


AA(1)A 
AA(2)AA(1)A 
AA(2)A 

AA 

AA(I)A 
AA()A 

AA 

AA 

AA 


D-48 


RU 
RU 
A 


COP rr rrr Yr D> > 


BBER 

BBLE 

CCEPT 
CCEPTABLE 
CCEPTANCE 
CCESS 
CCESSORY 
CCIDENTIAL 
CCOMPANY 
CCOMMODATION 
CCORDANCE 
CCORDING 
CCUPATION 
CCUPY 
CCEEDED 
CCESS 
CCESSFUL 
CCESSFULLY 
CCESSIVE 
cco 
CCESSFUL 
DD 
DDITIONAL 
DDRESSES 
DDRESS 
DDRESSED 
DDING 
DDER 

DDEN 
EEMENT 
EEN 

EEDED 
EENNEEDED 


SPESSESSSE SESS SSS SEES 


AA(S)A 
AA(S)ACI)A 


5 


AA(S)A 
AA(6)A 


BESEESSS 


EEN 

EENFORCE 
EENFORCEMENT 
EENLIST 
EENLISTED 
EENLISTMENT 


AA 
AA 
AA 
AA 
AA 
AA(DA 


SIXT 
SMOKESCR 
SP 


ro) 
mammmnmnmFSOodo 


GENERALSTA 
INE 
JUMPO 


Table D—7 ). List of words containing like letters repeated at various intervals (U}-Continued 


EENTH 
EEN 

EED 

EEL 

EET 

EEDED 
EEPING 
EEN 
EENTH 

EE 

EEK 

EEL 

FFAIR 
FFEUR 
FFICINT 
FFEE 
FFERENCE 
FFERENT 
FFICULT 
FFICULTIES 
FFECT 
FFECTED 
FFECTIVE 
FFICACY 
FFICIENT 
FFICIENCY 
FFORT 

FF 
FFICIENCY 


FFENDED 
FFENSE 
FFENSIVE 


FFICIENT 
FFIC 
GGAGE 
GGY 
GGLER 


PELELELELEELELELEEETLLELLLLLEL EL EEE EE ERErErEE 


LLEGE 
LLEGIANCE 
LLIED 
LLIES 
LLOCATION 
LLOTMENT 
LLOWANCE 
LLOW 

LLY 

LLERY 
LLISTICS 
LLOON 
LLIGERENT 


LLED 


LLECTION 
LLEGE 
LLISION 
LLED 


D-49 


D-50 


AA(B)A 


GONFIDENTIAL — 


Table D—7 (¥). List of words containing like letters repeated at various intervals (U)-Continued 


REPE 
RESPECTFU 
SHE 

SHE 

SHE 

SHE 

SHE 

SIGNA 

SMA 

SPE 
SUCCESSFU 


LLEGAL 
LLITERATE 
LLNESS 
LLUMINATE 
LLUMINATING 
LLUMINATION 
LLUSTRATE 
LLUSTRATION 
LL 

LLATIONS 
LLIGENCE 
LLIGENT 


“LLED 


LLING 
LLIMETER 
LLANEOUS 
LLATE 
LLAX 
LLEL 


LLATTACK 
LLIAM 
MMODATION 
MMETER 
MMUNITION 
MMA 
MMAND 


PBESSESES SSS SSS SS 


AA 
AA 
AA 
AA(2)A(4)A 


MMANDANT 
MMANDED 
MMANDEER 
MMANDER 
MMANDING 
MMENCE 
MMENCEMENT 
MMEND 
MMENDATION 
MMENT 
MMERCE 
MMISSARY 
MMISSION 
MMISSIONER 
MMIT 
MMITMENT 
MMITTEE 
MMON 
MMUNICATE 
MMUNICATION 
MMUNIQUE 
MMUTE 

MMER 
MMEDIATE 
MMIGRATION 
MMABLE 
MMEND 
MMENDATION 
MMENDED 
MMARY 
MMER 

MMIT 

MMON 
MMING 

NNEX 
NNOUNCE 
NNOUNCEMENT 
NNUAL 


NNEL 
NNECTING 
NNECTION 
NNER 


AA 
AA(I)A 
AA 

AA(LI)A 
AA(S)A 
AA 

AA(6)A 


AA 
AA(6)A 
AA 
AA(7)A 
AA(2)A 


CONFIDENTIAL— 


Table D—7 eh. List of words containing like letters repeated at various intervals (U)#«Continued 


SCH 
SHARPSH 
S 

SP 


NNER 
NNING 
NNEL 


. NNING 


NNAISSANCE 
NNOITER 
NNOITERING 


OOK 
OOPERATE 
OOPERATION 
OORDINATE 
OORDINATION 
OOTHOLD 
OON 


OOL 


OOTER 


BEESEESEE SEE 


: 
> 


~~ 


2A 


SESSSCSSS SSS SSSSCS SSS SSSS SSS SSS eS SES 


>P Pr rr rrr rrrr rrp 


PPARATUS 
PPARENT 
PPARENTLY 
PPEAR 
PPEARANCE 
PPEARED 
PPLICATION 
PPLY 

PPOINT 
PPOINTED 
PPOINTMENT 
PPROACH 
PPROPRIATE 
PPROVAL 
PPROVE 
PPROXIMATE 
PPER 

PPEAR 
PPEARANCE 
PPEARED 
PPED 

PPEN 

PPING 

PPOSE 
PPOSITE 
PPOSITION 
PPINES 
PPOINTED 
PPOINTMENT 
PPING 

PPED 

PPLIES 

PPLY 

PPORT | 
PPORTING 
PPOSE 
RRANGE 
RRANGEMENT 
RREST 
RESTED 
RRIVAL 
RRIVE 
RRACKS 
RRAGE 
RRIAGE 
RRIER 

RRY 


D-51 


D-52 


AA 
AA 
AA 
AA 
AA 
AA(S)A 
AA(S)A 
AA(S)A 
AA 
AA(1)A 


TRANSFE 
TRANSFE 
TU 

ACCE 
ACCE 
ACRO 
ADDRE 
ADDRE 
ADDRE 
ADMI 
AMBA 
ASPO 

A 


GONFIDENTIAL— 


Table D—7 (9). List of words containing like letters repeated at various intervals (U) #Continued 


RRED 

RRECT 
RRECTED 
RRECTION 
RRECTNESS 
RRESPONDENCE 
RRESPONDING 


RREGULAR 
RREGULARITIES 
RREGULARITY 
RRIGATION 
RROR 


RRENDER - 


AA A 
AA A 
AA(6)A A 
AA(I)AA(4)A A 
AA(4)A ASSE 
AA A 
AA(2)A A 
AA A 
AA A 
AA(7)A A 
AA(I)A A 
AA(1)A A 
AA(1)A A 
AA A 
AA A 
AA(4)A A 
AA A 
AA A 
AA BUSINE 
AA CARELE 
AA(2)AA CARELE 
AA CARELESSNE 
AA(I)A CHA 
AA CLA 
AA COMMI 
AA COMMI 
AA COMMI 
AA COMPA 
AA COMPLETENE 
AA COMPRE 
AA CONCE 
AA CONFE 
AA CONGRE 
AA CONGRE 
AA CORRECTNE 
AA CRO 
AA CRO 
AA(4)A CRO 
AA DARKNE 
AA DEPRE 
AA DISCU 
AA DISCU 
AA DISCU 
AA DISMI 
AA DISMI 
AA DI 
AA DI 


SSEMBLE 
SSEMBLY 
SSEMBLIES 
SSESSMENTS 
SSMENTS 
SSET 

SSETS 
SSIGNED 
SSIGNMENT 
SSIGNMENTS 
SSIST 
SSISTANT 
SSISTANCE 
SSOCIATE 
SSOCIATION 
SSOONAS 
SSURANCE 
SSURE 


SSIS 
SSIFICATION 
SSARY 
SSION 
SSIONER 


SSAL 
SSEMINATED 
SSEMINATION 


DISTRE 


GONFIDENTIAL — 


Table D—7 d. List of words containing like letters repeated at various intervals (U) Continued 


SSITY 


SSED 
SSENGER 
SSES 
SSIVE 
SSPORT 
SSION 
SSION 


AA(1)AA PO 
AA PO 
AA PREPAREDNE 
AA PRE 


fo 


2A VE 


SESE EE EEEEERESEEE 
5 


FESS ESSE ESS ee eee ee SS 
eoee 2 § 


SSESSION 


TTACH 
TTACHMENT 
TTACK 
TTAIN 
TTAINMENT 
TTEMPT 
TTEMPTED 
TTENTION 
TTALION 
TTEN 
TTERED 
TTERIES 
TTERY 
TTLE 
TTLEFIELD 
TTLESHIP 
TTER 

TTER 

TTOM 

TT 


D-53 


D-54 


CONFIDENTIAL — 


Table D-7 (9). List of words containing like letters repeated at various intervals (U) —Continued 


BSESSESSSS SSS SES 


- 


A 
A 

A 
A-A 
A-A(2)A 
A~A 
A-A 
A-A 
A-A 
A~A 
A-A(2)A 
A-A(2)A 
A-A 
A-A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A- 
A-A 
A-A 
A-A 
A-A 


AA 
AA 
AA 
A- 
A- 
A~ 


CIGARE 
COMMI 
COUNTERA 


ALM 


APP 
APPE 


ANALYSIS 
ANALYZE 
ARATUS 
ARANCE 
ARABIA 
AVAILABLE 


ATASTROPHE 
AVALRY 
ARACTER 
ARACTERISTIC 
ARANCE 


Ca ee eae 
rr rPrrrr rr rrr > 


| 


lt io 


{ 


| 
z 
LS 
> 


| 


eG hie a a ee ee 
>>> >> 


{ 


A-A(I)AQG)A 


1 
<4 
> 

> 


{ 


Ce Cel Toe Rae ae ced ae: 
rrr PrP rr rrr rr rrr rrr erry 


DISAPPE 
EXC 
EXC 

EXPL 


SEa 


Zz 
> 
ZAZ“A<d 224 


NONCOM 


ow 


PA 


eo as Mas Ma~ la ~All «) 


ATANT 
ABAND 
AMAGE 
AMAGED 
AMAGING 
ARANCE 
AVATE 
AVATION 
ANATION 
ATAL 
ATALITY 


ANAGE 
ANAGEMENT 
AVAL 
AVALATTACK 
ALATTACK 
AVALBASE 
AVALBATTLE 
AVALFORCES 
ATANT 
ANAMA 

AMA 
ARACHUTE 
ARADE 
ARAGRAPH 
ARALLAX 
ARALLEL 
ARATION 
AMATION 
ARANTINE 
ALARY 
ARATE 
ARATION 
AXATION 
ACANCY 
AWAL 

BABLE 
BABLY 
CYCLE 
CYCLONE 
CACY 

CYCLE 


A~A BEENNEE 
A-A BLOCKA 
A—A BOMBAR 
A-A COMMAN’ 
A—A DECI 
A-A 

A-A 

A-A DEFEN 
A-A DEMAN 
A-A ENCO 
A-A EXPAN 
A-A EXPEN 
A-A EXTEN 
A~A GROUN 
A-A GUAR 
A-A INVA 
A-A LAN 
A-A OFFEN 
A-A PROCEE 
A-A RAI 
A-A RECOMMEN 
A-A SUCCEE 
A-A SUSPEN 
A-A UNEXPEN 
A-A woo 
A-A WOUN 
A-A 

A-A AGRE 
A-A ALL 
A-A AMM 
A—A AMUS 
A-A ANNOUNC 
A~A ARRANG 
A-A BAROM 
A-A BATT 
A-A BEENNE 
A-A BELLIG 
A~A BESI 
A-A BILL 
A-A BRE 
A~A BRIDG 
A-A CAR 
A-AQ3)A CAR 
A-A CEM 
A-A(DA Cc 
A-A CENT 
A-A CHE 


Table D—7 (p). List of words containing like letters repeated at various intervals (U) “Continued 


DED 
DED 
DED 
DED 
DED 
DEDICATE 
DEDICATION 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DED 
DID 
EMENT 
EGE 
ETER 
EMENT 
EMENT 
EMENT 
ETER 
ERED 
EDED 
ERENT | 
EGED 
ETED 
EZE 
EHEAD 
ELESS 
ELESSNESS | 
ETERY 
EMETERY 
ERED 
ESE 


A-A 
A-A 
A-A 
A-A 


“A-A 


A-A(1)A 
A-A 
A-A(2)A 
A-A 
A-A 
A-A 
A~A 
A—A(2)A 
A-A(7)A 
A-A(7)A 
A-A 
A-A 
A—A(2)A 
A-A 
A-A(4)A 
A-A 
A—A(2)A 
A-A(2)A 
A~A(2)A 
A-A(4)A 
A-A 
A—A(2)A 
A-A 
A-A 
A-A(S5)A 
A—A(2)A 
A~A 
A—A(2)A 
A—A(2)A 
A-A 
A-A 
A—A(6)A 
A-A 
A-A(4)A 
A—A(4)A 
A-A 
A—A(3)A 
A-A(4)A 
A-A 
A-A(2)A 
A-A - 


“A-A 


COLL 
COMMENC 
COMPL 
COMPL 
COMPLET 
COMPL 
CONCR 


DECIPH 


DISPLAC 


_ DYNAMOM 


EGE 

EMENT 
ETELY 

ETE 

ENESS 
ETENESS 

ETE 

ERENCE 
EMENT 

ERED 

ERED 
EDENTIAL 
ECEMBER 
ECENTRALIZE 
ECENTRALIZED 
ERED 

EFEAT 
EFEATED 
EFECT 
EFECTIVE 
EFEND 
EFENDER 
EFENDED 
EFENSE 
EFENSIVE 
EFER 
EFERRED 
EPEND 
EPENDABILITY 
EPENDABLE 
EPENDENT 
ESERT 
ESERTED 
ESERTER 
ETECTOR 
ETENTION 
ETERIORATE 
ETERMINATION 
ETERMINE 
ETERMINED 
EVELOP 
EVELOPED 
EVELOPMENT 
ERENT 
ERENCE 
EMENT 

ETER 


D-55 


D-56 


ihe 
> Pr > >r >> D> 


EL 
EL 


EL 
ELSEWH 


EMPLAC 


ENCIPH 
ENCOUNT 


ENFORC 
ENGAG 
ENTANGL 


EXCIT 


EXTR 


-CONFIDENTIAL— 


Table D—7 (G). List of words containing like letters repeated at various intervals (U) Continued 


ELECTRICITY 
EMENT 
EMENTARY 


‘ELEMENT 


ELEMENTARY 
ELEVATE 
ELEVATION 
ELEVEN 


EMERGENCY 
EMENT 

ERED 

ERED 
ENEMIES 
ENEMY 
ENEMYPLANES 
ENEMYTANKS 
EMENT 
EMENT 
EMENT 
EVERY 
EMENT 
EXECUTIVE 
EXERCISE 


ENERAL 
ENERALALARM 
ENERALST AFF 
ETER 

ETER 

EBEEN 

ERE 

ERED 

ETER 

ETER 

EBERG 

EMENT 
ETENCE 
ETENT 
EPENDENT 
ETERMINATE 
EREST 
ERESTING 
ERE 


A~A(2)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(6)A 
A-AA 
A-AA 
A-A 
A-A 
A-A 
A-A 
A-A(4)A 
A-A - 
A-A 
A-A 
A-A(I)A 
A-A(2)A 
A-A(1)AQ2)A 
A-A 
A-A 
A-A(2)A 
A-A(1)A(2)A 
A-A(2)A 
A-A 
A-A 
A~A(2)A 
A-A 
A-A 
A-A 
A-A 
A—A(2)A 
A-A(2)A 
A-A 
A-A(5)A 


MEASUR 
MEASUR 


MILLIM 
MOV 


ERENCE 
ETER 

ENE 

EPER 

ETER 

ERED 

EVEL 
EMENT 

ESE 

EMENT 
EMENTS 
ETEOROLOGICAL 
ETER 

ETER 
EMENT 
ECESSARY 
ECESSITY 
ECESSITATE 
ETEEN 
ETEENTH 
ETE 

ERED 

ESES 
ENETRATION 
ENETRATE 
ETER 
EMENT 

EDE 

ECEDE 
EDENCE 
ECEDENCE 
ECEDING 
EFER 
ERENCE 
EFERENCE 
EFERRED 
ESENT 
ESERVATION 
ESERVE 
EDED 

ETER 
EBELLION 
ECEIPT 
ECEIVE 
ECEIVER 
ECEIVING 
ECEPTACLE 


CONFIDENTIAL _ 


Table D—7 (p. List of words containing like letters repeated at various intervals (U) —Continued 


A-A 
A-A 
A-A(2)A 
A—A(1)A(2)A 
A-A 
A-A 
A-A 
A-A 
A—A(2)A 
A-A 
A—A(2)A 
A-A 
A-A(2)A 
A-A 
A~A(2)A 
A—A(2)A 
A—A(2)A 
A-A 
A—A(2)A 
A-A 
A-A 
A-A 
A-A(6)A 
A—A 
A~A 
A-A 
A—A(2)A 
A-A 
A-A(2)A 
A-A(2)A 
A-A 
A-A 
A-A 
A-A 
A~A(2)A 
A~A 
A-A(2)AA 
A-A(2)AA 
A—A 
A-A 
A~A(6)A 
A-A 
A-A 
A—A(I)A 
A~A 
A-A 
A-A 


REENFORC 
R 

REF 

'R 
REIMBURS 
REINFORC 
REINSTAT 


wn” 
les 
NZANNNNAMNNUAMN 


~“ 
a7) 
me 


EMENT 
EFER 
ERENCE 
EFERENCE 
EMENT 
EMENT 
EMENT 
EJECT 
EJECTED 
EJECTOR 
ELEASE | 
EVE 
EMEDIES 
EMEDY 
EMEMBER 
EPEATED 
EPEATER 
EPEL 
EPELLED 
EMENT 
ESENT 
ESENTATION 
ESENTATIVE 
EMENT 
ESEARCH 
ESERVATION 
ESERVE 
ETENTION 
EVENUE 
EVERSE 
EWED 

EME 

EVEL 

ELECT 
ELECTED 
EVEN 
EVENTEEN 
EVENTEENTH 
EVENTH 
EVENTY 
EVENTYFIVE 


A~A 


SUCCE 


EDED 
ERED 
ERED 
ELEGRAM 
ELEPHONE 


ERE 


FIFTEENTH 
FIFTH 
FIFTY 
GAGE 
GAGE 
GAGEMENT 
GAGING 
HTH 

HTHE 
IVITY 

ITIES 
IVITIES 
ITIONAL 
INISTRATIVE 
INISTRATION 
ISING 

ITION 
TAIRCRAFT 
ICIPATE 
ICIPATION 
ICIAL 
IFICIAL 
ILITY 
IBILITY 
ILITY 
IFICATE 
ILIAN 
[VILIAN 
IFICATION 
ITION 
ICIENT 


D-57 


D-58 


A-A 
A-A 
A-A 
A-A 
A~A(2)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A—A(1)A 
A-A(1)A 
A—A 
A-A 
A-A 
A-A 
A-A 
A-A 
A—A(1)A 
A-A 
A-A(3)A 
A-A 
A~A 
A-A 
yas 
A-A(1)A 
A-A 
A-A(I)A 
A-A 
A—A 
A-A 
A-A 
A-A 
A-A(D)A 
reer 
A-A(I)A 
A-A 
A-A 
A—A 
A-A 
A-A 
A-A 
A-A 
A—A(I)A 
A-A 
A-A 


COLL 


CGONFIDENFIAL—__ 


Table D—7 @. List of words containing like letters repeated at various intervals (U) Continued 


ISION 
ISIONS 
ITION 


ITION 


ILIATION 
ITION 
ISIS 

ITIC 
ITICAL 
ICISE 
ICISM 
ITICISE 
ITICISM 
ITIQUE 
ISION 
ICIENCY 
ICIENT 
INITE 
ITION 
INITION 
ILIZE 
ILIZATION 
ILITY 
INING 
ITIAN 
INISH 
IMINISH 
IGIBLE 
IRIGIBLE 
ISINFECT 
ISINFECTED 
ITION 
IVIDE 
IDING 
IVIDING 
ISION 
IVISION 
ICIENT 
ICIENCY 
ICITY 
IGIBLE 
ISING 
IBITED 
ITION 
IBITION 
ITING 
ITION 


A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(DA 
A-A(3)A 
A-A 
A-A 
A-A 
A~A 
A-A 
A-A(1)A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A(3)A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A(3)A 
A-A 
A-A 
A~A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(2)A 
A-A 
A-A 
A-A 
A-A 


FACIL 
FAC 


IN 


IRREGULAR 
LIAB 


ITIES 
ILITIES 
ILING 
INISH 
IRING 
IFIED 
ILITY 
ITIES 
ILITIES 
IFICATION 
ITION 
INING 
IVIDUAL 
ICIENCY 
ITIAL 
INITIAL 
ITIATE 
INITIATE 
ITIES 
{LITY 
IAISON 
IMIT 
IMITATION 
IMITING 
ITING 
INING 
ITIME 
ICINE 
ILITARY 
ILITIA 
ITIA 
INIMUM 
INING 
ILIZATION 
ILIZE 
ITIONS 
INING 
ICIAL 
INION 
ITION 
IFIC 
ITION 
ILIPPINES 
ITICAL 
ITICS 
ITION 
ITIONS 


A-A 
A-A 
A-A(3)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(3)A 
A~A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A~A(1)A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A(3)A 
A-A 
A-A(3)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(3)A 
A-A 
A-A(1I)A 
A-A 


468-095 O - 72-21 


SPEC 
SUFF 
SUITAB 
SUSP 
SUSP 
SUSP 
TERR 
TRAD 
TRA 
TRANSPAC 
UNIDENT 
UT 

VER 

VIC 

Vv 

VISIB 


CONFIDENTIAL _— 


Table D—7 (). List of words containing like letters repeated at various intervals (U) —Continued 


ITIVE 
IRIE 
IMINARIES 
IMINARY 
IBIT 

ISION 
ISIONS 
IMITY 
IFICATION 
IDING 
INING 
IVING 
ITION 
ITING 
INING 
IRING 
ISITION | 
ITION 
IBILITY 
ILITY 
IRING 
IDING 
IGID 

IGID 
IRIGID 
ICING 
IFICANT 
IFICANCE 
IMILAR 
IMILARITY 
IFIC 
IFICATION 
ICIENT 
ILITY 
ICION 
ICIONS 
ICIOUS 
IFIC 
ITIONAL 
INING 

IFIC 

IFIED 
ILITY 
IFICATION 
INITY 
ICINITY 
ILITY 


A-A(I)A 
A~A(I)AQ)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
ASA 
A-A 
A-A 
A-A 
A-A 
A-A 
A—A(6)A 
A-A 
A-A 
A-A 
A—A 
A-A 
A-A 
A~A 
A-A 
A-A 
A-A 
A-A - 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A~A 
A-A 
A—A(4)A 
A-A(4)A 
A-A 
A-A 
A-A(7)A 
A~A 
A-A..- 
A-A 
A-A 
A-A 
A-A 


Vv 


H2ceec sn 


IBILITY 
[SIBILITY 
ISIBLE 


MEMORANDUM 
MEMORIAL 
MUM 
MEMBER 
MOMETER 
NONYMOUS 
NING 

NING 
NENTAL 
NING 
NANCE 
NANT 

NING 

NING 

NANT 

NING 
NANCE 
NING 

NING 

NING 

NAN 

NINE 
NINETEEN 
NINETEENTH 
NINETY 
NINTH 
NONCOMBATANT 
NING 
NANCE 
NENT 

NING 

NING 

NING 


A-A 
A-A 
A-A 
A-A 
A-A(2)A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A 


A-A(I)A 


A-A 
A—A(I)A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A—A(2)A 
A-A(3)A 
A-A 
A-A 
A-A 
A—A(I)A 
A-A 


ei 


mee 


-GONFIDENTFIAL— 


Table D—7 (p. List of words containing like letters repeated at various intervals (U) Continued 


NING 

NING 

NING 

NING 
NKNOWN 
OMOBILE 
OLOGICAL 
ONOLOGICAL 
OLON 
OLONEL 
OLORS 
ONOMIC 
ONOR 
OMOTIVE 
OCOMOTIVE 
OKOUT 
OLOGICAL 
OROLOGICAL 
OPOLY 
ONOPOLY 
OTOR 
OTORCYCLE 
OTORIZED 
OBOE 
OTOGRAPHY 
OMOTE 
OMOTION 
OPORTION 
OPOSALS 
OPOSE 

OCOL 
OTOCOL 
OVOST 
OROUS 
OLON 
OMORROW 
OPOGRAPHIC 
OROUS 
PAPER 
PAPERS 

PIPE 
POPULATED 
POPULATION 
RCRAFT 
RDROME 
RCRAFT 
RARY 


A-A 
A-A 
A-A 
A-A 
A-A 


RTRIDGE 
RYRUN 
RPRISE 
RPRISING 
ROR 

RPRINT 
RTRESS 
RPRETATION 
RPRETER 


SIS 
SESSMENT 
SESSMENTS 
SIST 
SISTANT 
SISTANCE 
SES 

SIS 

SIS 
SES. 
SASTER 
SES 

SES 

SES 

SES 

SES 

STS 

SES 

SIS 

SES 
SISTENT 
SESSION 
STS 

SES 

SIST 
SISTANCE 
SESSION. 
SISTENCE 
SUSPECTED 
SUSPEND 
SUSPENDED 
SUSPENSE 


A-A(3)A 
A-A 
A-A(6)A 
A-A(6)A 
A-A 
A=A 
A—A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A 
A-A(1)A 
A-A 
A-A(I)A 
A-A(1I)A 
A-A 
A-A(I)A 
A-A 
A-A 
A-A 
A-A 
A-A(L)A 
A~A 
A-A 


REPRESEN 
REPRESEN 


CONFIDENTIAL — 


Table D—7 (9). List of words containing like letters repeated at various intervals (U) Continued 


SUSPENSION - 


SUSPICION 
SUSPICIONS 
SUSPICIOUS 
SYSTEM 
SES 
TITUDE 
TITANK 
TATION 
TITION 
TATION 
TUTE 
TUTING 
TITUTING 
TUTION 
TITUTE 
TITUTION 
TUTE 
TITUTE 
TATED 
TATOR 
TITIAN 
TUTION 
TITUTION 
TATION 
TATION 
TITUDE 
TATION 
TATE 
TITION 
TATION 
TATE 
TATEMENT 
TATIVE 
TATIONS 
TATION 
TATEMENT 
TATES 
TATION 
TATIONS 
TATISTICS 


ttl ttt 
rrr Pr rrr rr rr Dd 


1 Ge a 


A(2)A(2)A 
A(2)A(2)A 
A(2)A 


—AQ2)A 


A(2)A 
A(2)A 
A(2)A(I)A 
A(2)A 
A(2)A 
A(2)A(2)A 
A(2)A(1)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 


TEN 


TRANSPOR 
UNITEDS 
WI 

A 

CONTIN 

F 

INA 

UN 


AL 


AMB 


AR 


TATIVE 
TITLE 
TOTAL 
TOTALING 


UGURATION 
USUAL 
UNUSUAL 
USUAL 

VIVED 
WKWARD 
ADJACENT 
ADVANCING 
ANTAGEOUS 
ANTAGE 
ADVANTAGE 
ADVANTAGEOUS 
ADVANCE 
ADVANCED 
AFFAIR 

ASKA 
ALMANAC 
ALWAYS _ 
ASSADOR 
AMBASSADOR 
APPARATUS 
APPARENT 
APPARENTLY 
ABIA 

AREA 
ARMAMENT 
ARRANGE 
ARRANGEMENT 
ASIA 

ASIATIC 
ASSAULT 
ATLANTIC 
ATTACH 
ATTACHEMENT 
ATTACK 
ATTAIN 
ATTAINMENT 


D-61 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
AQ)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 


AV 


AAANAAAIADAwBwW 


CGONFIDENTIAL — 


Table D—7 (q). List of words containing like letters repeated at various intervals (U) —Continued 


AILABLE 
AVIATION 
AVIATOR 
AGGAGE 
ARRACKS 
ARRAGE 
ATTALION 
AMPAIGN 
ANVAS 
APTAIN 
ASUAL 
ASUALTIES 
ASUALTY 
APLAIN 


ARKATION 
ACUATE 
ACUATING 
ACUATION 
ALUATION 
ADUAL 
AMMABLE 
ALLATIONS 
ANTANEOUS 


ALIATION 
APLANES 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(Q2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(6)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 


VETERIN 
W 

WILL 
ATOMIC 


DIVE 
HEAVY 
LIGHT 
MEDIUM 


EN 


ANDARD 
ANDARDS 
ATHAVE 
ATLANTIC 
ANSATLANTIC 
ARIATION 
ARIAN 

ARFARE 
ATTACK 

BOMB 

BARBED 

BOMB 

BOMBARD 
BOMBARDED 
BOMBARDMENT 
BOMBER 

BRIBE 

BRIBERY 

BULB 

BOMBER 
BOMBER 
BOMBER 
BOMBER 
CANCEL 
CANCELLATION . 
CANCELLED 
CHECK 

CIRCLE 

CIRCUIT 
CIRCUITOUS 
CIRCULAR 
CIRCULATE 
CIRCULATION 
CIRCUMSTANTIAL 
CIRCUMSTANCES 
CONCEAL 
CONCEALMENT 
CONCENTRATE 
CONCENTRATING 
CONCENTRATION 
CONCERNING 
CONCESSION 
CONCILIATION 
CONCLUDE 
CONCLUSION 
CONCRETE 
CIRCLE 


CONFIDENTIAL — 


Table D—7 . List of words containing like letters repeated at various intervals (U) —Continued 


A(2)A EN CIRCLING A(2)A CONVAL ESCENT 
AQ)A IMPRA CTICABLE’ A(2)A CONV ENIENT 
AQ)A PRA CTICAL A(2)A CORR ECTED 
A(Q2)A SE. CRECY A(2)A CORRESPOND ENCE 
A(2)A SIGNIFI CANCE A(2)A DEC EMBER 
A(2)A TA CTICAL A(2)A DECIPH ERMENT 
A(2)A TA CTICS A(2)A DECR EASE 
A(2)A VA CANCY A(2)A DECR EASED 
A(2)A HUN DRED | A(2)A(2)A D ECREASE 
A(2)A IN DEED A(2)A(2)A D ECREASED 
A(2)A ONEHUN DRED A(Q2)AA D ECREE 
AQ2)A STAN DARD A(2)A DEF EATED 
A(2)A STAN DARDS A(2)A DEF ENDER 
A(2)A ABS ENCE A(2)A DEF ENDED 
A(2)A ADDR ESSED A(2)A DEF ENSE 
A(2)A ADDR ESSES A(2)A DEF ENSES 
A(2)A AGR EEMENT A(2)A DEF ERRED 
A(Q2)A APP EARED A(2)AA D EGREE 
A(2)A ARR ESTED A(2)A DEP ENDENT 
A(2)A BATT ERIES A(2)A DEPRESSION 
A(2)A BATTL EFIELD A(2)A DES ERTED 
A(2)AA(I)A BE ENNEEDED A(2)A DES ERTER 
A(2)A BEENN EEDED A(2)A DIFFER ENCE 
A(2)A BE ETLE A(2)A DISAPP EARED 
‘AQ)AQ)A B ESIEGED A(2)A DIS EASE 
A(2)A B ETTER A(2)A . DISINF ECTED 
A(2)AA B ETWEEN A(2)A DISP ERSED 
A(2)A BR EEZE A(2)A DISP ERSE 
A(2)A CANC ELLED A(2)A DISTR ESSED 
A(2)A C EASE A(2)A EAGER 
AQ2)A C ENTER A(2)A ECHELON 
A(2)A(1)A C ENTERED A(2)A(3)A ECHELONED 
A(2)A C ENTERING A(2)A(4)A ECHELONMENT 
A(2)A CHALL ENGE A(2)A EDGE 
A(2)A CH EESE i} A(2)A EFFECT 
A(Q2)A ° CIGAR ETTE I AQ2)A EFF ECTED 
A(Q2)A COINCID ENCE | AC2)A(2)A EFFECTED 
A(2)A COMM ENCE 1 A(2)A(4)A EFFECTIVE 
A(2)A(1I)A COMM ENCEMENT i A(2)ACDA ELS EWHERE 
A(2)A COMM ERCE A(2)A(2)A(1)A 

A(2)A COMP ELLED A(2)A EM ERGENCY 
A(2)A COMPR ESSED A(2)A ENCIPH ERMENT 
A(2)A COND EMNED A(2)A EN EMIES 
A(2)A COND ENSED A(2)A ENT ENTE 
A(2)A CONFER ENCE A(2)A(2)A ENTENTE 
A(2)A CONF ERRED A(2)A ENTER 
A(2)A CONFID ENCE AQ)A ENTERING 


~CONFIDENTIAL— D-63 


A(2)A 
A(2)A(S)A 
A(2)A(6)A 
A(2)A 
A(2)A(3)A 
A(QQ)A 

A(2)A 

A(2)A 
A(2)A(4)A 
A(2)A 

A(2)A 

AQ)A 
A(2)A(3)A 
A(2)A 
A(2)A(2)A 
AQ)A 

A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A(2)A 
A(2)A(2)A(2)A 
A(2)A(3)A 
A(2)A 

A(2)A 
A(2)A(2)A 
A(Q2)A 

A(2)A 
A(2)A(4)A 
A(2)A 

A(2)A 

AQ)A 
A(2)A(6)A 
A(2)A FI 
A(2)A 
AQ)A 
A(2)A H 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 


EXT 


INCOMPET 
INCR 
INDEP 

INF 
INFLU 
INTELLIG 


—GONFIDENTIAL — 


Table D—7 ~). List of words containing like letters repeated at various intervals (U) —Continued 


ENTERPRISING 


‘ENTERPRISE 


ENTERTAINMENT 
ENVELOP 
ENVELOPE 
ETHER 

EXCEPT 

EXCESS 


_ EXCESSIVE 


EXPECT 
EXPEDITING 
EXPEDITION 
EXPEDITE 
ELLED 
EXPELLED 
EXPEND 
ENDED 
EXPENDED 
ENSES 
EXPENSES 
EXPENSIVE 
ENCE 
ERIENCE 
EXPERIENCE 
EXPERIMENT 
EXTEND 
ENDED 
EXTENDED 
EXTENDING 
EXTENSION 
EXTENSIVE 
EXTENT 
EXTERIOR 
EXTERMINATION 
EXTERMINATE 
ERCE 

EASE 

EBEEN 
ELPER 
ESSED 

ENCE 

ENCE 

EASED 
ENDENT 
ECTED 

ENCE 

ENCE 


A(2)A INT 
A(2)A INTERC 
A(2)A(2)A INT 
A(2)A INTERFER 
A(2)A INT 
A(2)A()A INT 
A(2)A(1)A(2)A INT 
A(2)A INT 
A(2)A(4)A INT 
A(2)A INT 
A(2)A(I)A INT 
A(2)A INT 
A(2)A INV 
A(2)A K 
A(2)A L 
A(2)A i 
A(2)A L 
A(2)A(I)A E 
A(2)A LIC 
A(2)A Ll 
A(2)A MAN 
A(2)A MAT 
A(2)A M 
A(2)A M 
A(2)A MESS 
A(2)A(2)A ... M 
A(2)A N 
A(2)A N 
A(2)A NEGLIG 
A(2)A NIN 
A(2)A NIN 
A(2)A NORTHW 
A(2)A NOV 
A(2)A OBS 
A(2)A OBS 
A(2)A OFF 
A(2)A OFF 
A(2)A OVERWH 
A(2)A PASS 
A(2)A PRECED 
A(2)A PREFER 
A(2)A PREF 
A(2)A PREPAR 
A(2)A PRES 
A(2)A PR 
A(2)A PROC 
A(2)A PROT 


ERCEPT 
EPTED 
ERCEPTED 
ENCE 
ERFERING 
ERFERE 
ERFERENCE 
ERMENT 
ERMEDIATE 
ERVENING 
ERVENE 
ERVENTION 
ENTED 
EEPER 
EADER 
EAVE 
ETTER 
ETTERED 
ENSE 
EUTENANT 
EUVER 
ERIEL 
EAGER 
EMBER 
ENGER 
ESSENGER 
EARER 
EAREST 
ENCE 
ETEEN 
ETEENTH 
ESTERN 
EMBER 
ERVE 
ERVER 
ENDED 
ENSE 
ELMED 
ENGER 
ENCE 
ENCE 
ERRED 
EDNESS 
ERVE 
ESSED 
EEDED 
ECTED 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)AQ(I)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)AC(IA 
AQ2)ACL)A 


AQ2)ACI)A(6)A 


A(2)A 
A(2)A 
A(2)A(Q2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)AQ)A 
A(2)A 
A(2)A(I)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
“A(2)A(2)A 
A(2)A 
AQQ)AQ2)A 
A(2)A 
A(2)AA 
A(2)AA 
A(Q2)A 


7 BB no 


Fe be 


ANNNNADA<S <wawDD 


—CONFIDENTIAL— 


Table D—7 (&. List of words containing like letters repeated at various intervals (U) —Continued 


ESTED 

EIVE 

EIVER 

ENDED 
ECREATION 
ECREATIONAL 
ENCE 

ECTED 

EASE 

ELIEF 

ELIEVE 

EDIES 

EMBER 

EATED 

EATER 

ELLED 
EPRESENT 
EPRESENTATION 
EPRESENTATIVE 
EQUEST 

ESTED 
EQUESTED 
ERVE 

ERVES 


_ ESPECT 


ESPECTFULLY 
ESPECTS 
ETREAT 
ENUE 

ERSE 
EVIEW 
EVIEWED 
EVIEWING 
EALEVEL 
EAMEN 
ECRECY 
ECRETARY 
FIZE 
ECTED 
ENCE 
ENTENCE 
EMBER 
EPTEMBER 
ERGEANT 
ENTEEN 
ENTEENTH 
ELLED 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A(L)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(5)A 
A(2)ACL)A 
AQ)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 


ESTERN 
EAMER 
ENCE 
EEDED 
ENDER 
ENDERED 
ECTED 
ENDED 
ENSE 
EMPERATURE 
EATENED 
ERRED 
ERSE 

ERSE 

ELVE 
ENDED 
EXPENDED 
ESSEL 
ESSELS 
EDNESDAY 
ESTERLY 
ESTERN 
ETHER 
ESSES 
ECKED 
ESTERDAY 
GGAGE 
GING 

GING 

GING 
GAUGE 
GEOGRAPHIC 
GEOGRAPHICAL 
GUAGE 
GLIGENT 
GLIGENCE 
GZAG 
HIGH 
HIGHER 
HIGHEST 
HATHAVE 
HETHER 
HICH 
ISSION 
IRFIELD 
TATIC 
IATION 


-GONFIDENFIAL — 


Table D—7 (eh. List of words containing like letters repeated at various intervals (U) —Continued 


AQ)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(1)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)AQGB)A 
AQ)A 
A(2)AG)A 
A(2)A(3)A 
A(2)A(3)A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)AC)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A(3)A 
A(2)A(3)A 
A(Q2)A 
AQ)AC)A 
A(2)A 
A(2)A 
AQ)A(2)A 


AV 

BALL 

BALL 

BEG 

B 

BU 
CHARACTER 


DISC 


ouoUD 


DISTING 


Gq 


S) 
z~AUOO 


tt) 
mn n o 


INFL 
INS 


IATION 
ISTIC 

ISTICS 
INNING 
INDING 
ILDING 
ISTIC 
INCIDENCE 
ISSION 
ISSIONER 
IATION 
IPTION 
IPTIVE 
IPTION 
IETITIAN 
IFFICULT 
IFFICULTIES 
IPLINE 
ISCIPLINE 
ISMISS 
ISMISSAL 
ISTILL 
ISTINCTION 
ISHING 
ISTINGUISH 
ISTINGUISHED 
ISTINGUISHING 
IFTING 
ISTING 
ILLING 
INDING 
ISHING 
ITTING 
IGNITION 
ILLITERATE 
IMMIGRATION 
INCIDENCE 
INCIDENT 
INDICATE 
INDICATED 
INDICATING 
INDICATION 
INDIRECT 
INDIVIDUAL 
ICTING 
IGNIA 
INSIGNIA 


A(2)A 
A(2)A(3)A 
A(2)A(3)A 
A(2)A 
A(2)A(D)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(1)A 
A(2)A(I)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 


jo) 


SSEB3EB 2220 reer wz 


ICTION 
INVITATION 
IRRIGATION 
ILLING 
IABILITY 
IFTING 
IQUID 
ISTICS 
IDNIGHT 
ILLIMETER 
ISFIRE 
ISFIRES 
ISSING 
ISSION 
ISSIONS 
IOTIC 
ISSION 
IPPINES 
INCIPAL 
INCIPLE 
INTING 
IORITY 
IATION 
ILLING 
ICTION 
TATION 
IEWING 
IPPING 
IGNIFICANT 
IGNIFICANCE 
IGNIFY 
INKING 
IRMISH 
ISTICS 
ISSION 
IORITY 
IMMING 
ISSION 
IATION 
ICTIM 
ILLIAM 
ITHIN 
LABLE 
LOIL 

LLEL 
MITMENT 
MAIM 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)AA 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A(S)A 
A(2)A(6)A 
A(2)A 
AQ2)A 
A(2)A()A 
AQ2)A(I)A 
A(2)A(2)A 
A(Q2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A(5)A 
A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A(4)A 
A(2)A(5)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
AQ)A 
A(2)A 
A(2)A 


CORRESPO 
CORRESPO 
DEPE 
DISCONTI 
DISCO 
DISCO 
ECHELO 


mmm mm 


ENTERTAI 
EXTE 

FI 

FLA 

FORE 
GOVER 


CONFIDENTIAL — 


Table D—7 (eV. List of words containing like letters repeated at various intervals (U) —Continued 


MBOMBER 


NOUNCEMENT 
NTENNA 
NMENT 
NMENTS 
NMENT 

NNING 

NDING 

NDANT 

NDING 
NCENTRATE 
NCENTRATING 


NCENTRATION - 


NDENSED 
NFINE 
NFINEMENT 
NTINENTAL 
NTINGENT 
NGENT 
NTINUAL 
NTINUE 
NTINUOUS 
NTINUATION 
NIENT 
NVENIENT 
NDENCE 
NDING 
NDENT 
NUANCE 
NTINUE 
NTINUANCE 
NMENT 
NGINE 
ENGINEER 
NGINEERING 
NTANGLEMENT 
NTENTE 
NMENT 
NDING 
NDING 
NKING 

NOON 
NMENT 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(3)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(3)A 
A(2)A 
A(2)A(I)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)A(S)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A 
A(2)A 


I 

I 
INDEPE 
I 

I 

INSTA 


AAAAANAAAwWMDW 


ie) 
ra 
mn 
4 


m 
Zo 


NCENDIARY 
NCENTIVE 
NDENT 
NFANTRY 
NLAND 
NTANEOUS 
NTEND 
NTENSIVE 
NTENT 
NTENTION 
NMENT 
NVENT 
NVENTED 
NVENTION 
NDING 
NTENANCE 
NGANESE 
NNING 
NOON 

NION 

NTING 
NNING 
NTON 

NTING 
NTINE 
NNING 
NTENCE 
NTINEL 
NKING 
NKEN 

NION 

NOWN 
NTENABLE 
OMMODATION 
ODROME 
OTTOM 
OYCOTT 
OMMON 
OMPOSED 
OMPOSITION 
ONFORMATION 
ONVOY 
ORPORAL 
ORPORATION 
OMHOUSE 
OCTOR 
ORMOUS 


A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 
AQ2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A 
A(2)AA 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(Q2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A(4)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 


EXPL 
EXPL 
F 

F 
FO 

G 
GYR 
t 

N 


-GONFIDENTIAL— 


Table D—7 (G. List of words containing like letters repeated at various intervals (U) —Continued 


OSION 

OSIONS 
OGHORN 
OLLOW 
OTHOLD 
ONIOMETER 
OSCOPIC 
OOKOUT 
ONCOMBATANT 
OBSOLETE 
OCTOBER 
OPPOSE 
OPPOSITE 
OPPOSITION 
OISON 

ONTON 
ONTOON 
OSTOFFICE 
OTION 
ONNOITER 
ONNOITERING 
OLHOUSE 
ORROW . 
ORIOUS 
PROPRIATE 
PROPER 
PREPARATION 
PREPARE 
PREPAREDNESS 
PREPARING 
PROPER 
PROPORTION 
PROPOSALS 
PROPOSE 


RMOREDCAR 
RMORY 

RIER 
RPORAL 
RPORATION 
RIER 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(4)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 


‘A(2)AA 


AQQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A(5)A 
A(2)A 
A(2)A(3)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 


DEPA 
DESE 
DETE 


RTURE 

RTER 
RIORATE 
RROR 

RIOR 
RAORDINARY 
RUARY 
RWARD 

RBOR 

RTERS 
ROGRAPHIC 
RFERE 
RFERENCE 
RFERING 
RIOR 

RROR 

RTAR 

RDER 

RVER 

RDER 
RDERED 
RDERS 
RAGRAPH 
RFORMANCE 
RAIRIE 
REARRANGED 
RIOR 

RIORITY 
ROGRAM 
ROGRESS 
ROGRESSIVE 
RTER 

RTERS 
RTERMASTER 
REAR 
REARGUARD 
RDER 
RECREATION 
RECREATIONAL 
RECRUIT 
RECRUITING 
REORGANIZATION - 
REPRESENT 
REPRESENTATIVE 
REPRESENTATION 
REPRISAL 
REPRISALS 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)AA 
A(2)A 
A(2)A(4)A 
A(Q2)AA 
AQ)AA(4)A 
AQ2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)AA 
A(2)A 
A(2)A 
A(2)A 
A(2)AA 
A(2)AA 
A(2)AA 
A(2)A 
A(2)AA 
A(2)AA 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)AA 
A(2)A 
A(Q2)A 
A(2)A 
AQ)ACI)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)AA 
A(2)A 
A(2)A 
AQ2)A 


CEN 


TRAN 
VES 
VI 
WITNE 


CONFIDENTIAL— 


Table D—7 (£). List of words containing like letters repeated at various intervals (U) ~Continued 


RETREAT 
RETROACTIVE 
RTER 

RIOR 
RIORITY 
RROR 
RFARE 

SSES 
SPOSSIBLE 
SESSMENT 
SESSMENTS 
SSESSMENT 
SSESSMENTS 
SETS 

SSIST 
SSISTANT 
SSISTANCE 
SNESS 
SORSHIP 
SSIS 

SERS 

SCUSS 
SCUSSED 
SCUSSION 
SEASE 
SMISSAL 
SMISS 
SPOSITION 
SIES 

SSES 

SSES 

SUES 

SSES 

SSES 
SESSION 
SSESSION 
SALS 

SALS 
SESSION 
SUBSISTENCE 
SUBSTITUTE 
SUBSTITUTION 
SUNSET 
SMISSION 
SELS 

SITS 

SSES 


A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A(6)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ2)A 
A(2)A 
AQ2)A 
A(2)A 


ADJU 
ADMINIS 
ADMINIS 


IMPOR 


TANT 
TRATIVE 
TRATION 
TRATION 
TANT 
TENTION 
TASTROPHE 
TANTIAL 
TANT 
TRATE 
TRATING 
TRATION 
TACT 
TRATE 
TRATED 
TRATION 
TECTOR 
TENTION 
TENTE 
TERTAINMENT 


TANT 
TANTANEOUS 
TANTLY 
TENT 
TENTION 
TANT 
TPUT 
TRATE 
TRATION 
TENT 
TECT 
TECTED 
TECTION 
TECTOR 
TEST 
TESTED 
TESTS 
TRATION 
TENTION 
TUATION 
TART 


D-70 


CONFIDENTIAL 


Table D—7 (ZS. List of words containing like letters repeated at various intervals (U) —Continued 


A(2)A 
A(Q2)A ST 
A(2)A 
A(2)A 
AQ)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(2)A()A 
A(2)A 
A(2)A 
A(2)A 
A(2)A 
AQ)AA 
A(2)A 
A(2)A WA 
A(2)A 
AQ2)A D 
A(2)A ) 
A(2)A 0 
P 
P 


ANNPMN 


A(2)A 
AQ)A 
A(2)A(6)A 


“AQQ)A 


A(2)A 
A(2)A 
A(2)A 
A(2)A 
A(3)A 
A(G3)A 
AG)A 
A(3)A(4)A 
A(3)A 
A(3)A 
A(3)ACI)A 
A(3)A 
A(3)A 
AG)A 
AG)A c 
A(Z)A Cc 
AG)A CENTR 
A(3)A CIRCUMST 
A(3)A DIS 
A(3)A DIS 
A(3)A E 
A(3)A EL 


BB he 


TARTER 
TISTICS 
TRATEGIC 
TRATEGICAL 
TRATEGY 
TACTICAL 
TACTICS 
TATOO 

TENT 
TENTATIVE 
TENTH 

TEXT 

THAT 
THATHAVE 
THATTHE 
TIETH 
TERTANK 
ULTURAL 
UGOUT 
UTGUARD 
UTPUT 
URSUE 
URSUIT 
UNSUCCESSFUL 
UNSUITABLE 
VOLVE 
VOLVER 
YWAY 
ZIGZAG 
ACTUALLY 
ANIMAL 
ANNUAL 
ANTIAIRCRAFT 
ANYWAY 
APPEAR 
APPEARANCE 
APPEARED 
AVERAGE 
AWKWARD 
ANADA 
ARRIAGE 
ALIZATION 
ANTIAL 
APPEAR 
APPEARED 
ASTWARD 
ABORATE 


A(3)A 
A(3)A 
AG)A 
A(3)A 
AG3)A 
AG)A 
A(3)A 
AG)A 
A(3)A 
AG)A 
AG)A 
AG)A 
A(3)A 
A(3)A 
AG)A 
A(3)A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
AG)A 


AGIA 


AQG)A 
A(3)A 
AQ)A 
AG)A 
A(3)A 
A(3)A 
AG3)A(4)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A(1)A 
A(3)A 
A(3)A 


NAT 


DEFI 
EFFI 

ELE 
GYROS 
INEFFI 
PA 

SPE 

SPE 

TE 
TRANSPA 


ATEDAT 
AMINATION 
ALALARM 
ALSTAFF 
ADQUARTERS 
ABORATORY 
ANGUAGE 
AINTAIN 
AINTAINED 
ANUF ACTURE 
ARSHAL 
ARTIAL 
ATURAL 
ATURALIZE 
ALIZATION 
ATURALIZATIOD 
AVIGATION 
ANIZATION 
ANAMA 
AILWAY 
ARGUARD 
AISSANCE 
ANIZATION 
ABOTAGE 
ANITARY 
ANITATION 
ARHEAD 
ANSPACIFIC 
CAPACITY 
CHURCH 
COINCIDENCE 
CONSCRIPTION 
COUNCIL 
CIENCY 
CIENCY 
CTRICITY 
COPIC 
CIENCY 

CIFIC 

CIFIC 
CIFICATION 
CHNICAL 
CIFIC 

DECIDE 
DECIDED 
DECODE 
DIVIDE 


-GONFIDENTIAL — 


Table D—7 (27. List of words containing like letters repeated at various intervals (U) ~Continued 


A(3)A DIVIDING AG3)A ENVELOPE 
A(3)A HIN DERED |] AGJA ERASE 
A(3)A INDIVIDUAL . A(3)A ERASER 
A(3)A MAN DATED A(3)A EXP EDITE 
AG)A OR DERED A(3)A EXP ERIMENT 
A(3)A RE DUCED A(3)A EXPRESS 
AG3)A SURREN DERED A(G)A(DA EXTREME 
A(3)A WE DNESDAY A(3)A FUSELAGE 
AG)A WIN DWARD A(3)A G EORGE 
A(3)A ASSEMBLE A(3)A GOV ERNMENT 
A(3)A ASSESSMENT A(3)A GR ENADE 
AG)A ASSESSMENTS A(3)A HEAVIER 
A(3)A ATT EMPTED A(3)A ILLIT ERATE 
A(3)A AV ERAGE A(3)A IMP EDIMENTA 
A(3)AA(A B EENNEEDED A(3)A INS ECURE 
AG)ACDA BE ENNEEDED A(3)A INT ERNMENT 
A(3)A BEETLE A(3)A INT ERPRETATION 
A()A . BEFORE AG)A(L)A INT ERPRETER 
AG)A BETWEEN A(3)A INT ERVIEW 
A(3)A CAREL ESSNESS A(3)A LEAGUE 
A(3)A C EMETERY A(3)A OP ERATE 
A(3)A COMPL ETENESS A(3)A(2)A OV ERWHELMED 
A(3)A CONC EALMENT A(3)A PAR  ENTHESIS 
A(3)A COOP ERATE AG)A(DA PAR  ENTHESES 
AG)A CORR ECTNESS AG3)A PRECEDE 
A(3)A DECIDE A(3)A(2)A PRECEDENCE 
A(3)A DECIDED A(3)A(2)A PREFERENCE 
AG)A D ECODE A(3)A PREPARE 
A(3)A DECREE A(3)A(2)A PR EPAREDNESS 
A(3)A D EGREE A(3)A PRESIDENT 
A(3)A DELAYED A(3)A PRESIDENTIAL 
AG)A DELIVER A(3)A PROC EDURE 
A(3)A DEV ELOPE A(3)A REACHED 
A()A DEVELOPED A(3)A RECOVER 
A(3)A DEVICE A(3)A REDUCE 
A(3)A D  EVISE A(3)A REDUCED 
A(3)A EASTERLY A(3)A(2)A REFERENCE 
A(3)A EASTERN A(3)A REFUGE 
A(3)A ECH ELONED A(3)AA REFUGEE 
A(3)A EITHER A(3)A REFUSE 
AG)A ELEMENT A(3)A REGIMENTAL 
AG)A ELEMENTARY A(3)A R_ EGIMENT 
A(3)A EL EVATE A(3)A RESCUE 
A(3)A ELEVEN A(3)A RESUME 
AG)A ENTRENCH A()A RETIRE 
A(3)A(3)A ENTRENCHED A(3)A SCH EDULE 

S ECURE 


AQG)A ENTR ENCHED AG)A 


—CONFIDENTIAL— D-71 


A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)AA 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AQG)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A()A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A(2)A 


D-72 


CLASSIF 
COMMUN 
CONST 
CONST 
COORD 
CR 

CR 

DED 

DEF 
DEMOBIL 
DETERM 
D 

D 
DISSEM 
DIST 
DIST 
DIST 
DIST 


CONFIDENTIAL 


Table D—7 (ef. List of words containing like letters repeated at various intervals (U) ~Continueq 


ETTLE 
ENTEEN 
ENTEENTH 
EVERE 
ESCREEN 
EARHEAD 
EFORE 
ENTIETH 
EATHER 
GARAGE 
GEORGE 
GOING 
HURCH 
HLIGHT 
HOSPHOROUS 
HOOLHOUSE 
HLIGHTS 
HATTHE 
HOUGH 
IVITIES 
IPATION 
ICATION 
IFICIAL 
IBILITY 
IGADIER 
IZATION 
IRCUIT 


_ IRCUITOUS 


ITATION 
ICATION 
ICATION 
ITUTING 
ITUTION 
INATION 
ITICISE 
ITICISM 
ICATION 
INITION 
IZATION 
INATION 
IMINISH 
IRIGIBLE 
INATION 
INCTION 
INGUISH 
INGUISHED 
INGUISHING 


A(3)A 
A(3)A 
A(3)A 
A(3)A(3)A 
A(3)A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG3)A(I)A 
AG3)A 
AG)A 
A(3)A 
A(3)A(2)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A(3)A 
A(3)A 
AG)A 
A(3)A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(G3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 


ISTRIBUTE 
IBUTING 
IBUTION 
ISTRIBUTING 
ISTRIBUTION 
ISTRICT 
ISTRICTS 
IVIDING 
IVISION 
IVISIONS 
INATION 
IRCLING 
IMATION 
INATION 
IBITION 
INATION 
INGUISH 
ILITIES 
IGHTING 
ILITIES 
ICATION 
INATING 
INATION 
INCLINING 
ICATING 
ICATION 
INFLICT 
INFLICTING 
INITIATE 
INQUIRE 
INQUIRY 
IRATION 
INSPIRATION 
INSPIRE 
ITUTION 
INSTITUTION 
IGATION 
IGATIONS 
ITATION 
IGATIONS 
ISSUING 
ITATION 
IMITING 
INTAIN 
INTAINED 
ILITIA 
IZATION 


A(3)A 
AG)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3Z)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A(DA 
A(3)A 
AG)A 
A(3)A 
AG)A 
AG)ACIA 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A()A 
A(G)A 
A(3)A 
AG)A 
A(3)A 
AG)A 
A(3)A(1)A 
A(3)A(IA 
A(3)A 
A(3)A 


AQG)A(4)A * 


A(3)A 
AG)A 
AG)A 
AG)A 
AG)AC)A 
AG)A 
A()A 
A(3)A 
AG)A 
A(3)A 
A(3)A 


NATURAL 


NAV 
ORGAN 
PRELIM 
QUALIF 
RECONNO 
REORGAN 
REQU 
RESPONS 

SAN 


SEA 


Table D—7 gs. List of words containing like letters repeated at various intervals (U) Continued 


{ZATION 
IGATION 
IZATION 
INARIES 
ICATION 
ITERING 
IZATION 
ISITION 
IBILITY 
ITATION 
IRIGID 
IGHTING 
ILARITY 
ICATION 
ITUTION 
ITABILITY 
ICATION 
INARIAN 
ICINITY 
IBILITY 
ISIBILITY 
LONEL 
LETELY 
LASHLIGHT 
LEGAL 
LEVEL © 
LITTLE 
LOCAL 
LEVEL 
MUSEMENT 
MMITMENT 
MAXIMUM 
MINIMUM 
MOVEMENT 
NATING 
NNOUNCEMENT 
NTENNA 
NTMENT 
NSION 
NTION 
NCERNING 
NDEMN 
NDEMNED 
NEMENT 
NTAIN 
NTION 
NSION 


A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A(2)A 
A(3)A 
A(3)A 
A(3)A(4)A 
A(3)A(2)A 
A(3)A 
A(3)A 
AG)A 
A(G3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)AA 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)AA 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 


ivy 
eS 
> mh 


PO 
REAPPOI 
RETE 
SEVE 
SEVE 
SUSPE 

U 

AIRC 

AN 

CHR 


NCOUNTERED 
NTRENCH 
NTRENCHED 
NSION 

NSION 
NATING 
NDEMNITY 
NSIGNIA 
NSTANT 
NSTANTLY 
NSTANTANEOUS 
NTION 
NTERNAL 
NTERNATIONAL 
NTERNMENT 
NTION 
NTRENCH 
NTION 
NCHING 
NEGUN 

NTAIN 
NTAINED 
NTAIN 
NOTING 
NEHUNDRED 


-NTOON 


NTMENT 
NTION 
NTEEN 
NTEENTH 
NSION 
NIDENTIFIED 
ONTROL 
ONYMOUS 
ONOLOGICAL 
ODEBOOK 
ONTROL 
ONTROVERSY 


’ OSSROADS 


ONTROL 
OOTHOLD 
ORENOON 
ORIZON 
ORATORY 
OCOMOTIVE 
OROLOGICAL 
ONOPOLY 


D-73 


A(3)A 
AG)A 
AG)A 
AG)A 
A()A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(GB)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A()A 
A(3)A 
AG)A 
A(3)A 
A()A 
A(3)A 
AG)A 
A()A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)AA 
AQG)A 
A(3)A 
A(3)A 
A(3)A 
AQG)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 


D-74 


vu sw vUVUUvvUNUUN 


~CONFIDENTIAL— 


Table D—7 (1 List of words containing like letters repeated at various intervals (U)—Continued 


OUTBOARD 
OUTPOST 
OUTPOSTS 
OSPHORUS 
ONTOON 
OSTPONE 
ORTION 
OTOCOL 
PPROPRIATE 
PASSPORT 
PHOSPHORUS 
POSTPONE 
PROMPT 
PSHIP 

PSHIPS 
RBITRATION 
RIBERY 
RRIER 
ROVERSY 
RIDOR 
ROSSROADS 
ROYERS 
ROYER 
RASER 
RTHER 
RTHER 
ROPER 
RETER 
RATORY 
RTHERN 
RTHERLY 
RATOR 
REARRANGED 
REFER 
REFERENCE 
REFERRED 
REPARATION 
REPARE 
REPAREDNESS 
REPARING 
RESCRIBED 
RESERVATION 
RESERVE 
RIMARY 
ROPER 
ROPORTION 
RAILROAD 


A(3)A REA 
A(3)A 

A(3)A(2)A 

A(3)A 

A()A 

A(3)A 

A(3)A 

AG)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A 

A(3)A SEC 
A(3)A 
A(3)A 
A(3)A 
A(3)A T 
A(3)A 
A(3)A A 
A(3)A A 
A(3)A A 
A(3)A(4)A A 
A(3)A A 
A(3)A 
A(3)A 
A(3)AA BU 
A(3)AA 
A(3)A 
A(3)A 
A(3)A DI 
A(3)A DI 
A(3)A DI 
A(3)A DI 
A(3)A Di 
A(3)A DI 


RGUARD 
RECORD 
RECORDER 
REDCROSS 
REFER 
REFERENCE 
REGARDING 
REPORT 
REPORTED 
RESERVATION 
RESERVE 
RESERVES 
RESTRAINT 
RESTRICTED 
RESTRICTION 
RETIRE 
RETIRING 
RETURN 
RETURNED 
RETURNING 
REVERSE 
RIGOROUS 
RIVER 
ROGER 
RETARY 


‘RATURE 


RITORY 
REFORE 
RAVERSE 
RINARIAN 
SCENSION 
SPOSSIBLE 
SSESSMENT 
SSESSMENTS 
SSETS 
STICS 
SHIPS 
SINESS 
SSNESS 
SNESS 
SIONS 
SCUSS 
SCUSSED 
SCUSSION 
SMISSAL 
SMISS 
SPERSE 


A(3)A 
A(3)A 
AG)AA 
A(3)AA 
AA 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
AG)A 
AG)A 
A(G)A 
A(3)A 
A(3)A 
A()A 
AG)A 
A(3)A 
A(3)AA 
A(3)A 
AG)A 
AG)A 
AG)A 
AG)A 
A(3)AA 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(G3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
AG)A 
AG)A 
A(3)A 
AG)A 
AG)A 
A(3)AA 
A(3)A 


468-095 O- 72 - 22 


~CONFIDENTFIAL— 


Table D—7 (2. List of words containing like letters repeated at various intervals (U) =-Continued 


SPERSED. 


. SPERSION 


STRESS 
STRESSED 
SIONS 
SSIES 
SIONS 
SSUES 
STICS 
SMANSHIP 
SAGES 
SIONS 
SSESSION 
SIONS 
SPONSIBLE 
SPONSIBILITY 
SATISFACTORY 
SATISFY 
SHIPS 
STICS 
STRESS 
SPENSE 
SPENSION 
SMISSION 


TIVITY 
TIVITIES 
TMENT 
TEDATING 
TMENT 
TLANTIC 
TEMPT 
TEMPTED 
TTENTION 
TOMATIC 
TMENT 
TMENT 
TITUTE 
TITUTION 
TRUCTION 
TRACT 
TERATTACK 
TMENT 


AQ)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A()A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 


TMENTAL 
TITUTE 
TRUCTION 
TONATE 
TONATED 
TONATION 
TINCTION 
TRICT 
TRICTS 
TEENTH 
TMENT 
TIMATE 
TIMATION 
TEDAT 
TIMATES 
TIMATEDAT 
TRACT 
TALITY 
TEENTH 
TEENTH 
TILITY 
TILITIES 
TERATE 
TITUTION 
TRUCT 


- TRUCTION 


TRUCTIONS 
TRUCTOR 
TIGATE 
TIGATION 
TIGATIONS 
TEENTH 
TRUCTIONS 
TPOST 
TPOSTS 
TRIOTIC 
TMENT 
TRUCTION 
TMENT 
TRICTED 
TRICTION 
TREAT 
TEENTH 
TEENTH 
TREET 
TITUTE 
TITUTION 


D-75 


D-76 


A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A(3)A 
A(3)A 
A(3)A 
AG)A 
AG)A 
AG)A(2)A 
A(3)A 
A(3)A 
AG)A(I)A 
AG)A - 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
A(3)A 
AG)A 
A(3)A 
A(3)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(DA 
A(4)A 


THIR 


TRANSA 


UNI 
U 
WARDEPAR 
WI 

B 

CHA 

CIRC 
COMM 

s 

S 


ANTI 


BE 


co 


GONFIDENTIAL — 


Table D—7 (p). List of words containing like letters repeated at various intervals (U) —Continued 


TAXATION 
THATTHE 
THIRTEEN 


. TEENTH 
’ THIRTEENTH 


THIRTY 
TRACT 
TRACTOR 
TLANTIC 
TWENTIETH 
TWENTY 
TWENTYFIVE 
TEDSTATES 
TILITY 
TMENT 
THOUT 
UREAU_. 
UFFEUR 
UITOUS 
UNIQUE 
URPLUS 
URROUND 
UNUSUAL 
WESTWARD 
WINDWARD 
ADJUTANT 
AERONAUTICS 
AIRCRAFT 
AIRPLANE 
ALASKA 
ALLOCATION 
ALLOWANCE 
ALMANAC 
AMBULANCE 
ANTEDATING 
AIRCRAFT 
ANTITANK 
APPARATUS 
APPROACH 
ARABIA 
ARRIVAL 
ASSURANCE 
AUTOMATIC 
AVAILABLE 
ACHHEAD 
AUSEWAY 
ASTGUARD 


A(4)A 
A(4)A 
A(4)A IN 
A(4)A 
A(4)A M 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(7)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A IN 
A(4)A ME 
A(4)A 
A(4)A RE 


Zz 
las) > 
AyvusZZaA<s2AYZYw“E 


ZE4nnsAw 


COIN 


APHICAL 
ACTICABLE 
AUGURATION 
ATIONAL 
ARKSMANSHIP 
ATERIAL 
ATIONAL 
ATIONALISM 
ATIONALITY 
AUTICAL 
ALATTACK 
AVALBASE 
AVALBATTLE 
ARAGRAPH 
ARALLAX 
ACTICAL 
AILHEAD 
AILROAD 
ATIONAL 
ATISFACTORY 
ATURDAY 
ACTICAL 
ARDEPA RMENT 
ATERTANK 
BLOCKBUSTER 
CHARACTER 


CHARACTERISTIC 


CHEMICAL 
CLERICAL 
CIDENCE 
COLLECT 
COLLECTION 
CONDUCT 
CONNECTING 
CONNECTION 
CONTACT 
CORRECTED 
CORRECTION 
CORRECTNESS 
CORRECT 
CRITIC 
CRITICAL 
CRITICISE 
CIDENCE 
CHANIC 
CEDENCE 
CEPTACLE 


Table D-7 &. List of words containing like letters repeated at various intervals (U) -Continued 


ACA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)ACL)A 
A(4)A(1)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(I)A 
A(4)A(I)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(1)A 
A(4)A(Q2)A 
A(4)A 
A(4)A 
A(4)A 
A(QA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(A 
A(4)A 
A(4)A 
A(DA 


CON 
CON 


PEckohohohohohek-AcRchohoh-LohoRoR-Rohon~) 


CRITICISM 
DEMNED 
DENSED 


‘DEFEND 


DEFENDER 


‘DEFENDED 


DEMANDED 
DEPEND 
DEPENDABLE 
DEPENDABILITY 
DEPENDENT 
DISLODGE 
DOWNED 
DEPENDENT 
ERNATE 
EMBLIES 
EACHHEAD 
ECAUSE 
EENNEEDED 
ELLIGERENT 
ESIEGED 
ENTERED 
ENCEMENT 
ENSATE 
ERENCE 
ERABLE 
ECEMBER 
ECIPHER 
ECIPHERED 
ECIPHERMENT 
ECLARE 
ECLARED 
EFEATED 
ECTIVE 
EFENDER 
EFENDED 
EFENSE 
EFENSES 
ENSIVE 
EFERRED 
EFICIENT 
EFICIENCY 
EMANDED ° 
EPARTED 
EPENDENT 
EPLOYED 
EPORTED 


A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)AA 
A(4)AA 
A(4)A 
A(4A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(L)A 
A(4)A 
A(4)AA 
A(4)AA 
A(4)A 
A(4)A 
A(4)A 


A(4)A 


A(4)A 
A(4)A(1)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(2)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(2)A 
A(4)A 


4+} A(4)A 


A(4)A 


ESERTED 
ESERTER 
ETACHED 
ERMINE 
ERMINED 
ELOPMENT 
ERENCE 
EBOMBER 
ELONMENT 
ECTIVE 
EIGHTEEN 
EIGHTEENTH 
EWHERE 
EMERGENCY 
ENCODE 
ENCODED 
ENEMIES 
ENGAGE 
ENGAGEMENT 
ENGINE 
ENGINEER 
ENGINEERING 
ENTIRE 
EUROPE 
EUROPEAN 
ESSIVE 
EXCITE 
EXCITEMENT 
ERCISE 
ERCISES 
ENSIVE 
ENSIVE 
EXIBLE 
EDIATE 
ESSIVE 
ENTIVE 
ETENCE 
EPENDENT 
ELLIGENT 
ELLIGENCE 
ENSIVE 
ERENCE 
ERFERE 
ERFERENCE 
EDIATE 
ERPOSE 
ERVENE 


D-77 


TONFIDENTIAL— 


Table D—7 (. List of words containing like letters repeated at various intervals (U) -Continued 


A(4)A LECTURE A(4)A REQUIRE 
A(4)A LETTERED A(4)A(I)A REQUIREMENT 
A(4)A MAINT ENANCE A(4)A RESERVE 
A(4)A(1)A M EASUREMENT A(4)A RESERVES 
A(4)A(IA M EASUREMENTS A(4)A RESTORED 
A(4)A M ESSAGE A(4)A RETURNED 
A(4)A M_ ESSAGES A(4)A REVENUE 
A(4)A MISCELLANEOUS A(4)A REVERSE 
A(4)A NEGLIGENT A(4)A REVIEWED 
A(4)A(2)A NEGLIGENCE A(4)A R EVOLVE 
A(4)A OBJ ECTIVE A(4)A R EVOLVER 
A(4)A OFF ENSIVE A(4)A | S EALEVEL 
A(4)A PEN ETRATE A(4)A S ELECTED 
A(4)A PERMANENT A(4)A SENTINEL 
A(4)A PREC EDENCE A(4)A S ERVICE 
A(4)A PREF ERENCE A(4)AA S EVENTEEN 
A(4)A PR EFERRED A(4)AA S EVENTEENTH 
A(4)A PR ESERVE A(4)A SMOK ESCREEN 
A(4)A PR ESSURE A(4)A SUCCESSIVE 
A(4)A PROGR ESSIVE A(4)A SURR ENDERED 
A(4)A RANG EFINDER A(4)A TEL EPHONE 
A(4)A READINESS A(4)A(DA TH ERMOMETER 
A(4)A RECEIVE A(4)A THR EATENED 
A()A RECEIVER A(4)A UNT ENABLE 
A(4)A . R ECOMMEND LE A(4YA VEHICLES 
A(4)A R ECOMMENDATION A(4)A FORTIFIED 
A(4)A(2)A R ECOMMENDED A(4)A EN GAGING 
A(4)A R ECORDER A(4)A FIGHTING 
A(DA REF ERENCE A(4)A SI. GHTING 
A(4)A REFUGEE A(4)A BREAKT HROUGH 
A(4)A REGISTER A(4)A S HARPSHOOTER 
A(4)A R EJECTED A(4)A T HROUGH 
A(4)A RELEASE A(4)A ARBITRATION 
A(4)A RELIEVE A(4)A CONCILIATION 
A(4)A REMEDIES A(4)A CONF IDENTIAL 
A(4)A R EMEMBER A(4)A CONF IRMATION 
A(4)A REPAIRED A(4)A CONF ISCATION 
A(4)A REPEATED A(4)A CONT INUATION 
A(4)A REPEATER A(4)A DES IGNATION 
A(4)A REPELLED A(4)A DIETITIAN 
A(4)A REPLACE A(4)A DIFF ICULTIES 
A(QA(DA REPLACEMENT A(4)A IMENSION 
A(4)A REPORTED A(4)A IRECTION 
A(4)A REPRESENT A(4)A(1)A ISPOSITION 
A(DA REPRESENTATION A(4)A ISSEMINATED 
A(4)A(6)A REPRESENTATIVE A(4)A(3)A ISSEMINATION 
A(4)A R EPULSED A(4)A INEERING 


CONFIDENTIAL — 


Table D—7 @. List of words containing like letters repeated at various intervals (U) —Continued 


A(4)A 
A(4)A 
A(A(A(Z)A 
A(4)A 
A(4)A 
A(4)A(3)A 
A(4)AQ)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(I)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(DA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(DA 
A(4)A 
A(DA 
A(4)A(I)A 
A(4)A 
A(A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4AA 
A(4)A 
A(4)A 
A(4)A 
A(DA 
A(4AA 
A(4)A 
A(DA 
A(4)A 
A(4)A 
A(4)A(Q2)A 
A(4)A 
A(4)A 


IMM 


AMMU 


IDENTICAL 
IDENTIFY 


IDENTIFICATION 


IGNITION 
ILLUMINATE 
ILLUMINATING 
ILLUMINATION 
IMMEDIATE 
IGRATION 
IMPEDIMENTA 
INDIVIDUAL 
INEFFICIENCY 
INHABITED 
INTERIOR 
INVADING 
INVASION 
ISLATION 
[ABILITY 
IONALISM 
IONALITY 
ILIPPINES 
IDENTIAL 
IGNATION 
IGNIFICANT 
IGNIFICANCE 
ITUATION 
IDENTIFIED 
ICTORIOUS’ 
LTURAL 
LEFIELD 
LIGIBLE 
LEXIBLE 
LLEGAL 
LEGISLATION 
LIABILITY 
LBATTLE 
MICBOMB 
MBARDMENT 
MENCEMENT 
MPARTMENT 
MPLOYMENT 
MPEDIMENTA 


MARKSMANSHIP 
‘MEDIUM 
MEDIUMBOMBER 


MILLIMETER 
NITION 


A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
ADA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(2)A 
AA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 


DETO 
DISSEMI 
DISTI 
DOMI 

E 

E 

ENGI 


NI 
NI 


NCEMENT 
NTITANK 
NGEMENT 
NTERING 
NCIDENCE 
NCEMENT 
NFERENCE 
NFIDENCE 
NFIDENT 
NFIDENTIAL 
NECTING 
NTINENTAL 
NATION 
NITION 
NATION 
NATION 
NATION 
NATION 
NCTION 
NATION 
NDURANCE 
NGAGING 
NEERING 
NTERING 
NTRAIN 
NTRAINED 
NATION 
NATION 
NATION 
NITION 
NATION 
NCIDENT 
NCIDENCE 
NDEPENDENT 
NFLUENCE 
NATIONAL 
NVADING 
NCTION 
NTENANCE 
NITIONS 
NATIONALITY 
NATIONAL 
NATIONALISM 
NETEEN 
NETEENTH 
NOTHING 
NGEFINDER 


D-79 


CONFIDENTIAL — 


Table D—7 (¢). List of words containing like letters repeated at various intervals(U) —Continued 


A(4)A RECOG 
ADA RESIG 
A(4)A ROADJU 
A(4A SIG 
A(4)A SY 
A(4)A U 
“A(4)A U 
A(4)A VETERI 
A(4)A ACCOMM 
A(4)A ALL 
A(4)A AT 
A(4)A c 
A(DA COMP 
A(4)A CORP 
A(4)A Cc 
A(4)A DEC 
_ A)A DET 
A(4)A DISP 
A(4)A F 
A(4)A INTR 
A(4)A L 
A(DA 
A(4)A OPP 
A(4)A 
A(A : P 
A(DA P 
A(4)A PR 
A(4)A PR 
A(4)A PR 
A(4)A PR 
A(4)A PR. 
A(4)A REV 
A(4)A REV 
A(4)A T 
A(4)A T 
A(4)A T 
A(4)AA 
A(4)A TO 
A(DA Al 
A(4)A ARMO 
A(DA CHA 
A(4)A CHA 
A(4)A Cl 
A(4)A CO 
A(4)A Cc 
A(4)A Cc 
A(4)A DI 
D-80 


NITION 
NATION 
NCTION 
NALLING 
NCHRONIZE 
NEXPENDED 
NKNOWN 
NARIAN 
ODATION 
OCATION 
OMICBOMB 
ODEBOOK 
OSITION 
ORATION 
ORRIDOR 
ORATION 
ONATION 
OSITION 
ORENOON 
ODUCTORY 
OCATION 
OPINION 
OSITION 
OVERCOMING 
OSITION 
OSITIONS 
OJECTOR 
OMOTION 
OTECTOR 
OVISION 
OVISIONS 
OLUTION 
OLUTIONARY 
OBACCO 
OMORROW 
ORPEDO 
PHILIPPINES 
POGRAPHIC 
RCONTROL 
REDCAR 
RACTER 
RACTERISTIC 
RCULAR 
RRIDOR 
RUISER 
RUISERS 
RECTOR 


A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
“A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A(3)A 
A(4)A 


EXTRAO 
FI 

INST 

NO 

P 

P 


RDINARY 
REALARM 
RUCTOR 
RTHWARD 
REFERRED 
RESSURE 
REPAIR 
REPAIRED 
REQUIRE 
REQUIREMENT 
REQUIRING 
RESEARCH 
RESOURCES 
RESTORED 
RUBBER 
RUNNER 
RENDER 
RENDERED 
RRITORY 
RACTOR 
RAILERS 
RAWLER 
RIGGER 
RDEPARTMENT 
SMENTS 
SOONAS 
SINESS 
SSNESS 
SROADS 
STRESS 
STRESSED 
SLANDS 
SSAGES 
SFIRES 
SSIONS 
SKIRTS 
SONERS 
SERVES 
SPECTS 
SHARPSHOOTER 
SHELLS 
SMOKESCREEN 
SPOOLS 
SPOONS 
STATES 
STATISTICS 


. STATUS 


AA 
A(4)A 
A()AA 
A(4)A 
A(4)AA 
A(4)AA 
A(4)AA 
A(4)AA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)AA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(Q)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(A 
A(QA 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 


Table D—7 (). List of words containing like letters repeated at various intervals (U) —Continued 


STRESS 
STRIPS 
SUBMISSION 
SUBSISTENCE 
SUCCESSIVE 
SUCCESS 
SUCCESSFUL 


’ SUCCESSFULLY 


SUGGEST 
SUNRISE 
SUPPOSE 
SPORTS 
STATES 
SUCCESSFUL 
SELESS 
TERNATING 
TERNATE 
TTEMPT 
TTEMPTED 
TERISTIC 
TINENTAL 
TINUATION 
TERATTACK 
TRIBUTE 
TRIBUTION 
TRIBUTING 
TRICITY 
TEMENT 
TALLATIONS 
TEGRITY 
TEREST 
TERESTING 
TERNATIONAL 
TENANT 
THEAST 
THWEST 
THWESTERN 
TSKIRTS 
TEMENT 
TRAINT 
TALIATION 
TROACTIVE 
THEAST 
THWEST 
THWESTERN 
TEMENT 
TATISTICS 


A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(4)A 
A(S)A 
A(S)A 


A(S)A 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(5)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(5)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 


MAN 


TARGET 
TENTATIVE 
TERRITORY 
THREAT 
THREATENED 
TRADITIONAL 
TURRET 
TWELFTH 
UMINOUS 
UFACTURE 
ACCEPTANCE 
ACCEPTABLE 
ACCOMPANY 
ACCORDANCE 


ADVANTAGEOUS 


ADVANTAGE 
AEROPLANE 
ALLEGIANCE 
ALTERNATING 
ALTERNATE 
AMBASSADOR 
AMERICAN 
ANTENNA 
APPEARANCE 
APPLICATION 
APPROVAL 
ARBITRARY 
ARBITRATION 
ASSISTANT 
ASSISTANCE 
ASSOCIATE 
ASSOCIATION 
ASSOONAS 
ABLEGRAM 
AMOUFLAGE 
ANCELLATION 
APPEARANCE 
AORDINARY 
AINTENANCE 
ALIFICATION 
ARTERMASTER 
ADIOGRAM 
ADIOSTATION 
ATEGICAL 
ANSATLANTIC 
CEPTANCE 
CORDANCE 


D-81 


D-82 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(GS)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 


A(S)A(2)A 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(GS)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 


Table D—7 @. List of words containing like letters repeated at various intervals (U) ~-Continued 


vovvunnUNDDUOURvvVNNUY 


iS) 
2) 
S 


CHRONICLE 
COEFFICIENT 
COMMENCE 


COMMENCEMENT 


COMMERCE 
CONFISCATION 
CONFLICT 
CONTACT 
CREPANCIES 
CREPANCY 
CONOMIC 
DRESSED 
DVANCED 
DGEHEAD 
DAMAGED 
DECIDED 
DELAYED 
DROPPED 
DICATED 
EPTANCE 
EPTABLE 
EGIANCE 
EARANCE 
ELESSNESS 
EARANCE 
EFFICIENT 
ENTRATE 
ESPONDENCE 


. ECREASE 


ECREASED 
EDICATE 
EFINITE 
EPARTMENT 
EPARTMENTAL 
ENDABLE 
EPLOYMENT 
ESCRIBE 
ESCRIBED 
ESTROYERS 
ESTROYED 
ESTROYER 
ETACHMENT 
ETONATE 
ETONATED 
ETRAINED 
EVELOPED 
EARANCE 


DISCR 
DISS 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
AG)A(IA 
AGS)A(DA 
A(S)AA 
A(S)A 
A(S)A(2)A 
A(S)ACIA 
A(S)A 
A(S)A(I)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(GS)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A EX 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A - 
A(S)A(2)A 
A(S)A 
AG)A 
A(S)A 
A(S)A IN 
A(S)A 
A(S)A 
A(S)A 
A(S)A J 
A(S)A M 
A(S)A M 
A(S)A N 
A(S)A N 
A(S)A ON 
A(S)A PAR 


ENT 


EXP 


EPANCIES 
EMINATED 
EFFECTED 
EFFICIENT 
EFFICIENCY 
EIGHTEEN 
EIGHTEENTH 
ELEVATE 
ELSEWHERE 
EMPLACEMENT 
EMPLOYEE 
EMPLOYER 
ENCIPHERMENT 
ENCIPHERED 
ENCIPHER 
ENFORCEMENT 
ENFORCE 
ENGINEER 
ENGINEERING 
ENLISTED 
ENROLLED 
ENTENTE 
ERPRISE 
EQUIPMENT 
ESCORTED .- 
EXCLUDE 
ECUTIVE 
EXPANDED 
EXPELLED 
EXPENDED 
EXPENSES 
ERIENCE 
EXPERIENCE 
EXTENDED 
EXTREME 
ERPLANE 
EFFICIENCY 
ERCEPTED 
ERPRETER 
ERRUPTED 
ETPLANE 
EDICINE 
ESSENGER 
EWSPAPER 
EWSPAPERS 
EHUNDRED 
ENTHESES 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
AGS)A(IA 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
AG)A 
AGS)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A | 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 


CONFIDENTIAL —— 


Table D—7 . List of words containing like letters repeated at various intervals (U) —Continued 


ERSISTENT 
ERSONNEL 
EMATURE 


’ ESCRIBED 


ERMASTER 
EPTACLE 
ENFORCEMENT 
ENFORCE 
ENLISTED 
EMAINDER 
EQUESTED 
ESOURCES 
EABORNE 
EAPLANES 
ENTENCE 
EPARATE 
EPTEMBER 
EVENTEEN 
EVENTEENTH 
ELLFIRE 
ERATURE 
ERRIBLE 
EREFORE 
EXPENDED 
ENTIFIED 
EDSTATES 
EPARTMENT 
GINNING 
GASSING 
GETTING 
GARDING 
HTEENTH 
ISTRATIVE 
ISTRATION 
ICIPATION 
IFICATION 
IDERATION 
ILIZATION 
ISCIPLINE 
ISCONTINUE 
ISCONTINUANCE 
ISCUSSION 
ISPERSION 
IFICATION 
IMPASSIBLE 
IMPOSSIBLE 
INCENDIARY 


A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A(2)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A(3)A. 
A(S)A(3)A 
A(S)A 
A(5)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 
A(S)A 


CHRONO 
C 
INF 


METEORO 
PO 
co 

E 
I 


REI 
COMME 
COMPE 


INCENTIVE 
INCLINING 
INCLUDING 
INCLUSIVE 
INDEMNITY 
INFLATION 
INSIGNIA 
INTEGRITY 
INTELLIGENCE 
INTELLIGENT 
INTENSIVE 
INTENTION 
INTERDICTION 
INTERDICT 
INTERVIEW 
INVENTION 
INVESTIGATION 
INVESTIGATIONS 
INVESTIGATE 
IMITATION 
ILIZATION 
IMINARIES 
IFICATION 
IOSTATION 
ISTRATION 


’ IGNALLING 


IMILARITY 
IFICATION 
ITABILITY 
IFICATION 
ISIBILITY 
LOGICAL 
LERICAL 
LAMMABLE 
LOGICAL 
LOGICAL 
LITICAL 
MMENCEMENT 
MPLACEMENT 
MPROVEMENT 
MANAGEMENT 
MARITIME 
MAXIMUM 
MINIMUM 
MBURSEMENT 
NDATION 
NSATION 


D-83 


CONFIDENTIAL — 


Table D—7 (1 List of words containing like letters repeated at various intervals (U) —Continued 


A(S)A CONCE NTRATING A(S)A PRINCIPAL 
A(S)A CO NCERNING A(S)A PRINCIPLE 
A(S)A CO NDITION A(S)A AI RSUPPORT 
A(S)A CO NNECTING A(S)A ARBITRARY 
A(S)A CON NECTION - A(S)A ARTILLERY 
A(S)A CO NTINGENT A(S)A BA ROMETER 
A(S)A CONTI NUATION A(S)A B REAKTHROUGH 
A(S)A CO NTRABAND A(S)A FI RECONTROL 
A(S)A CO NVENIENT A(S)A GENE RALALARM 
A(S)A DISCO NTINUANCE A(S)A GY ROMETER 
A(S)A E NEMYTANKS A(S)A HYD ROMETER 
A(S)A E  NLISTING A(S)A HYG ROMETER 
A(S)A ENTA NGLEMENT A(S)A INTE RPRETER 
A(S)A FOU NDATION A(S)A IR REGULAR 
A(S)A I NCLINING A(S)A IR REGULARITIES 
A(S)A INCLUDING || A(S)A IR REGULARITY 
A(S)A INTERMENT A(S)A PREMATURE 
A(S)A(3)A INTERVENTION A(S)A PRISONER 
A(S)ACI)A INTERVENING | A(S)A PRISONERS 
A(S)A INTERVENE A(S)A P ROCEDURE 
A(S)A INVASION | ACSA PSYCH ROMETER 
A(S)A MA NAGEMENT ACSA QUARTE RMASTER 

“ie A(GS)A RECOMME NDATION  A(S)A RADIOGRAM 

: A(GS)A RECON NAISSANCE | A(S)A RECOVER 
A(S)A REPRESE NTATION | A(S)A _ REENFORCE 

—AGS)A SIGNIFICANCE | A(S)A REENFORCEMENT 
A(S)A SIGNIFICANT | A(S)A REGISTRATION 
A(S)A TRA NSATLANTIC | ACSA REGULAR 
A(S)A ASS OCIATION i ACSA REIMBURSEMENT 
A(S)A C OALITION | A(S)A REINFORCE 
A(S)A C OLLISION 1 A(S)A REINFORCEMENT 
A(S)A C OLLISIONS ACSA ST RAGGLER 
A(S)A CONDITION | AGS)A SU RRENDER 
A(S)A CONF ORMATION | ACSA SU RRENDERED 
AG)A C ONTINUOUS  ACS)AA TRANSFERRED 
A(S)A C ORRESPONDENCE | A(5)AA T RANSFERRING 
A(S)A C ORRESPONDING “ AGS)A TRANSFER 
A(S)A F ORMATION i ACS)A T RANSPORT 
A(S)A INF ORMATION 1 ACSA T RANSPORTATION 
A(S)A INTRODUCTION | AGS)A T RANSPORTS 
A(S)A OPERATOR A(S)A T RANSVERSE 
A(S)A PR OPORTION  AGS)A ASSESSMENTS 
A(S)A PR OTECTION 4 ACS)A A SSOONAS 
A(S)A RADI OSTATION | AGA CIRCUM STANCES 
A(S)A REC OGNITION | A(S)A CRO SSROADS 
A(S)A TRANSPORTATION | ACSA DISTRICTS 
A(S)A PHILIPPINES ! A(S)A ESTABLISH 


A(S)A E 
A(S)A E 
A(S)A NEW 
A(S)A PHO 
A(S)A PO 
A(S)A RE 
A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A 

A(S)A UN 
A(S)A AN 
A(S)A AN 
A(S)A CER 
A(S)A CON 
A(S)A IDEN 
A(S)A INS 
A(S)A INS 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A(I)A IN 
A(GS)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A IN 
A(S)A QUAR 
A(S)A SA 
A(S)A SUI 
A(S)A 

A(S)A 

A(S)A()A 

A(S)A UNI 


—GONFIDENTIAL — 


Table D~—7 ee List of words containing like letters repeated at various intervals (U) —Continued 


STABLISHED 
STABLISHMENT 
SPAPERS 
SPHORUS 
SITIONS 
SOURCES 
SAILORS 
SECTORS 
SERIOUSLY 
SKIRMISH 
SUBMISSION 
SUCCESSIVE 
SUCCESS 
SUCCESSFUL 
SUCCESSFULLY 
SURPLUS 
SURPRISE 
SUSPENSE 
SUSPENSION 
SUCCESSFUL 
TICIPATE 
TICIPATION 
TIFICATE 
TINGENT 
TIFICATION 
TRUMENT 
TRUMENTS 
TERCEPT 
TERCEPTED 
TERDICT 
TERDICTION 
TERMENT 
TERPRETATION 
TERPRETER 
TERRUPT 
TERRUPTED 
TERRUPTION 
TERVENTION 
TRODUCTION 
TRODUCTORY 
TERMASTER 
TISFACTORY 
TABILITY 
TONIGHT 
TRAJECTORY 
TRANSATLANTIC 
TEDSTATES 


A(S)A 
A(S)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 


~ 


> fi 


DUUDUUUUUmwEr Ze 


S 
Or 


UBSTITUTE 
UBSTITUTION 
ANTICIPATE 
ANTICIPATION 
ASSIFICATION 
ARTMENTAL 
ADITIONAL 
ANSPORTATION 
CCEPTANCE 
CCORDANCE 
CERTIFICATE 
CUMSTANCES 
CLEARANCE 
COMMUNICATE 


COMMUNICATION 


CONSTRUCTION 
CONSTRUCTION 
DDRESSED 
DECLARED 
DEFEATED 
DEFENDED 
DEFERRED 
DEMANDED 


DEPARTED 


DEPLOYED 
DEPORTED 
DESERTED 
DETACHED 
DICTATED 
DISARMED 
DERSTAND 
DERSTOOD 
ERODROME 
EROPLANE 
EENNEEDED 
ELLIGERENT 
ECIPHERED 
EFECTIVE 
EFENSIVE 
EPARTURE 
ESIGNATE 
ESIGNATED 
ESPATCHES 
ESPATCHED 
ESTITUTE 
ERIORATE 
ETERMINE 


D-85 


A(6)A D 
A(6)A D 
A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A(1)A 

A(6)A EN 
A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A(L)A 

A(6)A ENT 
A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A EXT 
A(6)A 
A(6)A INV 
A(6)A M 
A(6)A M 
A(6)A M 
A(6)A NEC 
A(6)A OV 
A(6)A ?P 
A(6)A PR 
A(6)A PR 
A(6)A PR 
A(6)A PR 
A(6)A R 


D-86 


Table D—7 (eh. List of words containing like letters repeated at various intervals (U) —Continued 


ETERMINED 
EVELOPMENT 
ECHELONED 
ELIGIBLE 
EMBASSIES 
EMPLOYEE 
EMPLOYMENT 
ENCIRCLE 
ENCOUNTERED 
EMYPLANES 
ENFILADE 
ENGAGEMENT 
ENLISTMENT 
ENROLLMENT 


ENTANGLEMENT 


ERTAINMENT 
ENTRAINED 
ENVELOPE 
EQUALIZE 
EQUIPAGE 
EQUIVALENT 
ESTIMATE 
ESTIMATEDAT 
ESTIMATES 
EVACUATE 
EXCAVATE 
EXCHANGE 
EXCITEMENT 
EXERCISE 
EXERCISES 
EXHIBITED 
EXPEDITE 
EXPERIMENT 
ERMINATE 
ERMINATE 
ESTIGATE 
EASUREMENT 
EASUREMENTS 
ECHANIZED 
€SSITATE 
ERWHELMED 
ENETRATE 
EARRANGED 
ECEDENCE 
EFERENCE 
EPAREDNESS 
ECOGNIZE 


A(6)A 
A(6)A(L)A 
A(6)A 
A(6)A 
A(S)A 
A(6)A(L)A 
A(6)ACI)A 
A(6)A 
A(6)A(I)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A SEV 
A(6)A T 
A(6)A T 
A(6)A , 
A(6)A TH 
A(6)A TW 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A(2)A 
A(6)A DIS 
A(6)A 

A(6)A(3)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A 

A(6)A UN 


DARA DRM wD 


: 
B 


mw 


wRelonehonenenen— 


be 5 ae | 


EENFORCE 
EENFORCEMENT 
EENLISTED 
ENLISTMENT 
EFERENCE 
EIMBURSEMENT 
EINFORCEMENT 
EINFORCE 
EINST ATEMENT 
EINSTATE 
EPLACEMENT 
ENTATIVE 
EQUIREMENT 
ESTRICTED 
ENTY FIVE 
ECHNIQUE 
ELEPHONE 
ENTATIVE 
ERMOMETER 
ENTYFIVE 
GUISHING 
GROUPING 
GUARDING 
GNALLING 
IRCULATION 
IPLOMATIC 
ISORGANIZED 
ISPOSITION 
ISTINCTION 
ISTINGUISH 
ISTINGUISHED 
ISTINGUISHING 
INGUISHING 
INGERPRINT 
IDENTIFICATION 
IMPRACTICABLE 
IMPRESSION 
IMPRESSIVE 
INDICATING 
INDICATION 
INEFFICIENCY 
INFLICTING 
INSECURITY 
INSPECTION 
INVITATION 
IRRIGATION 
IDENTIFIED 


A(6)A 
A(6)A 
A(6)A 
A(6)A(2)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A. 
A(6)A: 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A ORGA 
A(6)A RECO 
A(6)A RECON 
A(6)A REE 
A(6)A REORGA 
A(6)A SA 
A(6)A TRA 
U 
Cc 
Cc 
Cc 


A(6)A 
A(6)A 
A(6)A 
A(6)A 


CONFIDENTIAL 


Table D-7 (ZS. List of words containing like letters repeated at various intervals (U) ~Continued 


ITHDRAWING 
MEASUREMENT 
MEASUREMENTS 
MORANDUM 
NTEDATING 
NICATION 
NCEALMENT 
NTRATION 
NCESSION 
NCLUSION 
NFESSION 
NFINEMENT 
NNECTION 
NGUISHING 
NCIRCLING 
NEMYPLANES 
NLISTMENT 
NROLLMENT 
NTERTAINMENT 
NTRUCKING 
NGERPRINT 
NDICATING 
NFLATION 
NFLICTING 
NSTANTANEOUS 
NSTRUMENT 
NSTRUMENTS 
NTENTION 
NTERNMENT 
NVENTION 
NEGLIGENT 
NEGLIGENCE 
NINETEEN 
NINETEENTH 
NORTHERN 
NUMBERING 
NIZATION 
NNAISSANCE 
NOITERING 
NLISTMENT 
NIZATION 
NITATION 
NSFERRING 
NDERSTAND 
OLLECTION 
OMMISSION 
OMMISSIONER 


A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 


A(6)A 


A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 


Q 
NOQOAANAN 


> 
bas a °] 


_— 


ONCESSION 
ONCLUSION 
ONFESSION 
ONNECTION 
OPERATION 
ORRECTION 
OMINATION 
OUNDATION 
OBJECTION 
OPERATION 
OPULATION 
OSSESSION 
PARAGRAPH 
RICULTURAL 
RIGADIER 
RODUCTORY 
RREGULAR 
RREGULARITIES 
RREGULARITY 
ROJECTOR 
ROTECTOR 
REARGUARD 
RECEIVER 
RECONSTRUCTION 
RECORDER 
REGISTER 
REJECTOR 
REMEMBER 
REPEATER 
REVOLVER 
RMOMETER 
RAJECTORY 
RANSFERRED 
RANSFERRING 
SEMBLIES 
SUALTIES 
STOMHOUSE 
SPATCHES 
STROYERS 
SPATCHES 
STINGUISH 
STINGUISHED 
STINGUISHING 
STIMATES 
SOLDIERS 
SOUTHEAST 
SOUTHWEST 


D-87 


D-88 


A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 


A(6)A. 


A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(6)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 


-GONFIDENTIAL— 


Table D—7 (K List of words containing like letters repeated at various intervals (U) —Continued 


CHARA 


SOUTHWESTERN 
STATIONS 
SUPPLIES 
SPICIONS 
SPICIOUS 
TACHMENT 
TAINMENT 
TRALIZATION 
TACHMENT 
TERIORATE 
TERMINATION 
TAINMENT 
TERMINATE 
TERMINATION 
TERMINATE 
TERNMENT 
TIONALITY 
TATEMENT 
TATEMENT 
TEMPERATURE 
TWENTIETH 
USTOMHOUSE 
ULTANEOUS 
UCCESSFUL 


_UCCESSFULLY 


USPICIOUS 
UCCESSFUL 
VENTYFIVE | 
WITHDRAW 
WITHDRAWAL 
WITHDRAWING 
WITHDREW 
ACCIDENTAL 
ACCOMMODATION 
ADDITIONAL 
APPROPRIATE 
APPROXIMATE 
ARMOREDCAR 
ARTIFICIAL 
ATURALIZATION 
CTERISTIC 
CLASSIFICATION 
CONFERENCE 
CONFIDENCE 
CONSPIRACY 
CONVALESCENT 
COMPETENCE 


A(7)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(1)A 
A(7)A 
A(7)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
AC7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(1)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 


armmwmazagdrus 


m 
~wanDn 


DECREASED 
DESCRIBED 
DESTROYED 
DETONATED 
DETRAINED 
DEVELOPED 
DISCUSSED 
DISPERSED 
DOMINATED 
DENTIFIED 
ENTRALIZE 
ENTRALIZE 
ENTRALIZED 
ENCIPHERMENT 
EMOBILIZE 
EPENDABLE 
ECHELONMENT 
EFFECTIVE 
ELABORATE 
EMPLACEMENT 
ENCIPHERED 
ENDURANCE 
ENFORCEMENT 
ENTRENCHED 
EXCESSIVE 
EXCLUSIVE - 
EXECUTIVE 
EXPANSIVE 
EXPENSIVE 
EXPLOSIVE 
EXTENSIVE 
EADQUARTERS 
EAVYBOMBER 
EAVYLOSSES 
ELLIGENCE 
ERMEDIATE 
EGLIGENCE 
EAPPOINTED 
ECEPTACLE 
ECOMMENDED 
ECONNOITER 
ECONNOITERING 
ENFORCEMENT 
EENLISTMENT 
ESISTANCE 
GINEERING 
HOTOGRAPHY 


A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
‘A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7))A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 

A(7)A 


“CONFIDENTIAL 


Table D—7 B. List of words containing like letters repeated at various intervals (U) —Continued 


Be 
UUVUUE BH 


HIRTEENTH 
INISTRATIVE 
INISTRATION 


-IFFICULTIES 


ISTRIBUTING 
ISTRIBUTION 
IMMIGRATION 
INDETERMINATE 
INFORMATION 
INSPIRATION 
INSTITUTION 
INSTRUCTION 
INSTRUCTIONS 
INTERESTING 
INTERFERING 
INTERMEDIATE 
INTERNATIONAL 
INTERVENING 
MECHANISM 
MEDIUMBOMBER 
NOUNCEMENT 
NGRESSIONAL 
NSTITUTING 
NSUMPTION 
NVALESCENT 
NSTRATION 
NFORCEMENT 
NGINEERING 
NCOMPETENT 
NCOMPETENCE 
NDEPENDENT 
NDETERMINATE 
NDICATION 
NEFFICIENCY 
NSPECTION 
NTELLIGENCE 
NTELLIGENT 
NTERESTING 
NTERFERENCE 
NTERFERING 
NTERVENING 
NVITATION 
NCOMBATANT 
NETRATION 
NNOITERING 
NFORCEMENT 
NFORCEMENT 


A(T)A 
A(7)A 
A(7)A 
A(1)A 
A(7)A 
A(T)A 
A(7)A 
A(T)A 
A(7)A 
A(T)A 
A(T)A 
A(7)A 
A(7)A 
A(T)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(1)A 
A(T)A 
A(7)A 
A(T)A 
A(T)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(7)A 
A(1)A 
A(7)A 
A(7)A 
A(7)A 
A(1)A 
A(7)A 
A(T)A 
A(7)A 
A(T)AC)A 
A(7)A 
A(7)A 
A(T)A 
A(8)A 
A(8)A 


“ACSA 


NSTATEMENT 
NSMISSION 
OMMODATION 
OMPETITION 
OMPOSITION 
OMPUTATION 
ONGRESSIONAL 
ONSUMPTION 
OOPERATION 
ORDINATION 
ORPORATION 
ONSTRATION 
OCCUPATION 
OPPOSITION 
OCLAMATION 
PHOTOGRAPHY 
RMOREDCAR 
RAORDINARY 
RTHWESTERN 
RELIMINARIES 
RELIMINARY 
REMAINDER 
RPSHOOTER 
SSEMBLIES 
SESSMENTS 
SIGNMENTS 
STILITIES 
STRUMENTS 
SUREMENTS 
SEAPLANES 
STANDARDS 
TTACHMENT 
TTAINMENT 
TIMATEDAT 
TELLIGENT 
TERMEDIATE 
TERPRETATION 
TURALIZATION 
THERMOMETER 
THIRTEENTH 
TRANSPORTATION 
TRANSPORT 
TRANSPORTS 
YESTERDAY 
ADMINISTRATIVE 
ADMINISTRATION 
ANTIAIRCRAFT 


D-89 


~GONFIDENTIAL— 


Table D—7 Pi. List of words containing like letters repeated at various intervals (U) —Continued 


A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(3)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A(L)A 
A(8)A 


DIS 


vou0Uwa 


<8 


a) 


a") 
ANA AAD ARD AAA WZ 


i) 


COINCIDENCE 
CONTINUANCE 
DECIPHERED 
DESIGNATED 
DESPATCHED 
DETERMINED 
DISPATCHED 
DISTRESSED 
ERTIFICATE 
ESPONDENCE 
EMONSTRATE 
EMONSTRATED 
ESCRIPTIVE 
ETERIORATE 
ENCIPHERMENT 
ENCOUNTERED 
ENEMYPLANES 
ENTANGLEMENT 
ENTERPRISE 
ESTABLISHED 
ETERMINATE 
EGULARITIES 
EDIUMBOMBER 
ECESSITATE 
ERFORMANCE 
ELIMINARIES 
EAPPOINTMENT 
EENFORCEMENT 
EIMBURSEMENT 
EINFORCEMENT 
EINSTATEMENT 
ESENTATIVE 
ESPONSIBLE 
ETROACTIVE 
EVENTYFIVE 
EMPERATURE 
HYDROGRAPHIC 
ISCREPANCIES 
ILLUSTRATION 
INAUGURATION 
INSTALLATIONS 
INTERDICTION 
INTERRUPTION 
INTERVENTION 
INTRODUCTION 
IRREGULARITIES 
IRREGULARITY 


A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 


“A(8)A 


A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 
A(8)A 


Q 
(e) ee eo es es | 


ZEZEaANQNQAQAAAANANODA 


MEMORANDUM 
NISTRATION 
NNOUNCEMENT 
NCELLATION 
NCENTRATING 
NCILLIATION 
NFIRMATION 
NFISCATION 
NFORMATION 
NSCRIPTION 
NSTITUTION 
NSTRUCTION 
NTINUATION 
NVERSATION 
NCIPHERMENT 
NTANGLEMENT 
NTERPRISING 
NFORMATION 
NSPIRATION 
NSTITUTION 
NSTRUCTION 
NSTRUCTIONS 
NTERNATIONAL 
NAVIGATION 
NSTRUCTION _ 
OMMENDATION 
OMPENSATION 
ONCILIATION 
ONFIRMATION 
ONFISCATION 
ONFORMATION 
ONSCRIPTION 
ONSTITUTION 
ONSTRUCTION 
ONTINUATION 
ONVERSATION 
OBILIZATION 
OBILIZATION 
OBSERVATION 
OBSTRUCTIONS 
OMMENDATION 
ONSTRUCTION 
OADJUNCTION 
RTERMASTER 
SSESSMENTS 
SSIGNMENTS 
STRUCTIONS 


CONFIDENTIAL — 


Table D~7 od. List of words containing like letters repeated at various intervals (U) —Continued 


STIGATIONS 
STRUCTIONS 
SENT ATIONS 
SCHOOLHOUSE 
SUBMARINES 
SUSPICIONS 
SUSPICIOUS 
TIAIRCRAFT 
TANGLEMENT 
AGRICULTURAL 
CHRONOLOGICAL 
CIRCUMSTANCES 
CONNAISSANCE 
DISAPPEARED 
DISINFECTED 
ECENTRALIZE 
ECENTRALIZED 
ENTERTAINMENT 
ESTABLISHMENT 
EXTERMINATE 
IRCUMSTANTIAL 
INVESTIGATION 
INVESTIGATIONS 
NTICIPATION 
NCENTRATION 
NSIDERATION 
NTERTAINMENT 
NTIFICATION 
NAUGURATION 
NSTALLATIONS 
NTERDICTION 
NTERRUPTION 
NTERVENTION 
NTRODUCTION 
NONCOMBATANT 
NSPORTATION 


OMMUNICATION 
ONCENTRATION 
ONSIDERATION 
ORGANIZATION 
ORGANIZATION 
RANGEFINDER 
RECONNOITER 
RECONNOITERING 
SCREPANCIES 
STALLATIONS 
STANTANEOUS 
SCELLANEOUS 
TERTAINMENT 
TABLISHMENT 
TRANSATLANTIC 
TRANSPORTATION 
UNSUCCESSFUL 
COUNTERATTACK 
DEMONSTRATED 
DISORGANIZED 
DISSEMINATED 
INTERPRETATION 
IRREGULARITIES 
NTRALIZATION 
NVESTIGATION 
NVESTIGATIONS 
NORTHWESTERN 
REVOLUTIONARY 
SEARCHLIGHTS 
SIMULTANEOUS 
CORRESPONDENCE 
DECENTRALIZED 
DISTINGUISHED 
ECONNAISSANCE 
NTERPRETATION 
NATURALIZATION 


468~095 O ~ 72 - 23 


APPENDIX q) 
USEFUL TABLES 


E-1 


CONFIDENTIAL— 


Table E—1 ). Expected number of repetitions, polyalphabetic ciphers (U) 


Number Expected number of diagraphs occurring exactly x times 
of 


Number 
of 
letters 


Number | Expected number of trigraphs 


of 
jeters | 22) | Bo) | Ce) | 


hs 
E(3) 


Es ~CONFIDENTIAL— 


-~GONFIDENTIAL — 


Table E~2 (p: Expected values of @, and @ p (U). 


468-095 O ~ 72 - 24 


CONFIDENTIAL— 


Table E—3 (y ).Factor table (U) 


NUMBERS 1-—400 
1 | Prime 36| 23469 12 18 70/25 710 14 35 
2 | Prime 37} Prime 71) Prime 
3 | Prime 38| 2 19 721234689 12 18 24 36 
4| 2 ; 39/ 3 13 73 | Prime 
5 | Prime 40| 245 8 10 20 74/2 37 
6| 23 41| Prime 75}3 5 15 25 
7 | Prime 42; 2367 1421 76\2 4 19 38 
8124 | 43| Prime 7717 11 
91 3 44] 2411 22 78123 6 13 26 39 
10| 25 451 35915 79 | Prime 
11 | Prime 46| 2 23 80|2 4.5 8 10 16 20 40 
12} 2346 47| Prime 81|3 9 27 
13 | Prime 481 2346 8 12 16 24 82/2 41 
14} 27 49| 7 83 | Prime 
15} 35 50} 25 10 25 84/23 467 12 14 21 28 42 
16/248 51] 317 85|5 17 
17 | Prime 52| 24 13 26 8612 43 
18| 2369 53| Prime 873 29 
19 | Prime 54] 2369 18 27 88|2 48 11 22 44 
20 | 245 10 551 5 11 89 | Prime 
26139 56) 247 8 14 28 90/2 3 5 69 10 15 18 30 45 
22} 211 57| 3 19 917 13 
23 | Prime 58] 2 29 9212 4 23 46 
24123468 12 59} Prime 93] 3 31 
25 | 5 60} 2345 610 12 15 94|2 47 
26 | 2 13 20 30 ; 95|5 19 
27139 61| Prime 96/2 3 4 6 8 12 16 24 32 48 
28 | 247 14 62] 2 31 97 | Prime 
29 | Prime 63} 37921 98/27 14 49 
30123561015 64) 248 16 32 99/39 11 33 
31 | Prime 65| 5 13 100|2 4 5 10 20 25 50 
32 | 248 16 66} 236 11 33 101 | Prime 
33 | 3 11 67| Prime 102|2 3 6 17 34 51 
34 | 217 68| 24 17 34 103 | Prime 
35} 57 69| 3 23 104} 2 4 8 13 26 52 


E CONFIDENTIAL— 


105 
106 
107 
108 


109 
110 
111 
112 
113 
114 
115 
116 
117 
118 
119 
120 


121 
122 
123 
124 
125 
126 


127 
128 
129 
130 
131 
132 


133 
134 
135 
136 
137 
138 
139 
140 


141 


Table E-3 (U). Factor Table (U)--Continued 
NUMBERS 1-400 -~ Continued 


35 7 15 21 35 

2 53 

Prime 
23469 12 18 27 
36 54 

Prime 

25 10 11 22 55 

3 37 
247 8 14 16 28 56 
Prime 

2 3 6 19 38 57 


6.7 9 14 18 21 
42 63 

Prime 

248 16 32 64 

3 43 

2 § 10 13 26 65 
Prime 
2346 11 12 22 33 


2 

3591 
248 17 34 68 
Prime 

2 3 6 23 46 69 
Prime 
245 7 10 14 20 28 


35 70 
3 47 


142 
143 
144 


145 
146 
147 
148 
149 
150 


151 
152 
153 
154 
155 
156 


157 
158 
159 
160 


161 
162 
163 
164 
165 
166 
167 
168 


169 
170 
171 
172 
173 
174 
175 
176 


177 


2 71 

11 13 
234689 12 16 
18 24 36 48 72 

5 29 

2 73 

3 7 21 49 

2 4 37 74 

Prime 
235610 15 25 30 
50 75 

Prime 

24 8 19 38 76 
3917 51 

11 14 22 77 


NUNN 


4 6 12 13 26 39 
52 78 


82 


178 
179 
180 


181 
182 
183 
184 
185 
186 
187 
188 
189 
190 
191 
192 


193 
194 


195 


196 
197 
198 


199 
200 


201 
202 
203 
204 


205 
206 
207 
208 


209 
210 


211 
212 


2 89 
Prime 


234569 10 12 15 


18 20 30 36 45 60 90 


Prime 


27 13 14 26 91 
3 61 
24 8 23 46 92 


21 27 63 
0 19 38 95 


3.46 8 12 16 24 
32 48 64 96 


Prime 


297 
3.5 13 15 39 65 
247 14 28 49 98 


Prime 


2369 i] 18 22 33 
66 99 

Prime 

245 8 10 20 25 40 
50 100 

3 67 

2 101 

7 29 
234 6 12 17 34 51 
68 102 

5 41 

2 103 

3 9 23 69 

248 13 16 26 

52 104 

11 19 

23567 10 14 15 
21 30 35 42 70 105 
Prime 

24 53 106 


213 
214 
215 
216 


217 
218 
219 
220 


221 
222 
223 
224 


225 
226 
227 
228 


229 
230 
231 
232 
+ 233 
234 


235 
236 
237 
238 
239 
240 


241 
242 
243 
244 
245 


E-6 


8 9 12 18 


Wa 


13 17 

23 6 37 74 111 
Prime 

247 8 14 16 28 
32 56 112 

359 15 25 45 75 
2 113 

Prime 

2346 12 19 38 
57 76 114 

Prime 

2 5 10 23 46 115 
3 711 21 33 77 
24 8 29 58 116 


Prime 

2369 13 18 26 

39 78 117 

5 47 

24 59 118 

3 79 

27 14 17 34 119 

Prime 

2345 68 10 12 


15 16 20 24 30 
40 48 60 80 120 
Prime 

2 11 22 121 

3 9 27 81 

2 4 61 122 

5 7 35 49 


-GONFIDENTIAL- 


Table E-3 (U). Factor Table (U)--Continued 


246 
247 
248 
249 
250 
251 
252 


253 
254 
255 
256 
257 
258 
259 
260 


261 
262 
263 
264 


265 
266 
267 
268 
269 
270 


271 
272 


273 
274 
275 
276 


277 
278 
279 


NUMBERS 1-400 --Continued 


2 3 6 41 82 123 
13 19 

24 8 31 62 124 
3 83 

2 5 10 25 S50 125 
Prime 


234679 12 14 18 
21 28 36 42 63 84 126 
11 23 

2 127 


3.5 15 17 51 85 

2 4 8 16 32 64 128 
Prime 

2 3 6 43 86 129 

7 37 

245 10 13 20 26 
52 65 130 

3 9 29 87 

2 131 

Prime : 
23468 11 12 22 
24 33 44 66 88 132 
$ 53 

2 7 14 19 38 133 

3 89 

2 4 67 134 

Prime 

23569 10 15 18 
27 30 45 54 90 135 
Prime 

248 16 17 34 68 
136 

3 7 13 21 39 91 

2 137 

5 11 25 55 

23 4 6 12 23 46 
69 92 138 

Prime 

2 139 

3 9 31 93 


280 


281 
282 
283 
284 
285 
286 
287 
288 


289 
290 
291 
292 
293 
294 


295 
296 
297 
298 
299 
300 


301 
302 
303 
304 


305 
306 


307 
308 


309 
310 
311 


245 78 10 14 20 
28 35 40 56 70 140 
Prime 

2 3 47 94 141 

Prime 

2471 142 

3.5 15 19 57 95 

2 11 13 22 26 143 
7 41 


234689 12 16 18 24 


32 36 48 72 96 144 


17 

25 10 29 58 145 
3 97 

24 73 146 

Prime 

2367 14 21 42 
49 98 147 

5 59 


24 8 37 74 148 
3.9 11 27 33 99 

2 149 

13 23 

2345 610 12 15 
20 25 30 50 60 75 
100 150 

7 43 

2 151 

3 101 

248 16 19 38 76 
152 

5 61 

2369 17 18 34 51 
102 153 

Prime 

24711 14 22 28 44 
77 154 

3 103 

25 10 31 62 155 
Prime 


~CONFIDENTIAL—— 


Table E-3 (U). Factor Table (U)--Continued 
NUMBERS 1-400 --Continued 


2346 8 12 13 24 
26 39 52 78 104 
Prime 

2 157 

3579 15 21 35 
45 63 105 

2 4 79 158 

Prime 

2 3 6 53 106 169 
11 29 

245 8 10 16 20 
32 40 64 80 160 

3 107 

2 7 14 23 46 161 
17 19 

23469 12 18 27 
36 54 81 108 162 

§ 13 25 65 

2 163 


3 109 
24 8 41 82 164 
7 47 


23561011 13 22 
30 33 55 66 110 165 
Prime 

2 4 83 166 

3 9 37 111 

2 167 

5 67 

23467 8 12 14 
16 21 24 28 42 48 
56 84.112 168 

Prime 

2 13 26 169 

3 113 

245 10 17 20 34 
68 84 170 

11 31 


2369 18 19 38 
57 114 171 

7 49 

2 4 8 43 86 172 

3 5 15 23 69 115 
2 173 

Prime 

2346 12 29 58 
87 116 174 

Prime 

25 7 10 14 25 35 
50 70 175 

3 9 13 27 39 117 
248 11 16 22 32 
44 88 176 

Prime 

23659 118 177 
5 71 

2 4 89 178 

3 7 17 21 51 119 
2 179 

Prime 
2345689 10 12 
15 18 20 24 30 36 40 
45 60 72 90 120 180 
19 

2 181 

3 11 33 121 

247 13 14 26 28 
52 91 182 

5 73 

23 6 61 122 183 
Prime 

248 16 23 46 

92 184 

3 9 41 123 

2 5 10 37 74 185 
7 53 


372,23 4 6 12 31 62 


93 124 186 

Prime 

2 11 17 22 34 187 
3.5 15 25 75 125 

2 4 8 47 94 188 

13 29 

23679 14 18 21 
27 42 54 63 126 
Prime 

245 10 19 20 38 
76 95 190 

3 127 

2 191 

Prime 

2346 8 12 16 24 
32 48 64 96 128 

§$ 711 35 55 77 

2 193 

3.9 43 129 

24 97 194 

Prime 

23°56 10 13 15 26 
30 39 65. 78 130 195 
17 23 

2478 14 28 49 
56 98 196 

3 131 

2 197 

5 79 

23469 11 12 18 
22 33 36 44 66 99 
132 198 

Prime 

2 199 

3 7 19 21 57 133 
245 8 10 16 20 25 
40 50 80 100 200 


E-7 


-CONFIDENTIAL— 


Table E—4 Yh. Table of primes up to 2000 (U) 


Es | SCONFIDENTIAL 


“ 
INDEX (2) 
a ahaa Gace, stele Paragraph Page 
Accidental repeats in ‘periodic polvalohabetic systems_.__....-----.---------- Fe ee hoe ce ht 12-7 12-5 
Addressee, see definition. 
Advantages of code systems. _..._...------.--------------------------------------------+----- lied 15-8 
Alphabet: 
Cipher. 223 2226s ele et ee eet othe de is ce ceeube sl aol i eS Be ie 1-8a 1-3 
COMponents-.2o sages het Sota tes lei se ee sed elena ooh ret See se een estes eee ee eke T-2¢ 7-1 
Wal, Watures.. bole esoesb wat cost eta eteh ees cnessp ecb betta gs beets tee oeoten ee ebas Sik 7-2a T-1 
Enciphering; suse.c....0 se acne eect ees ae Suc oe le Se eae esa edkteest sae T-Ta 7-3 
Mixed:cipher= 522-0 te olh oo oe tes twee See be cue ies cee et See eee Ss seek oe T-4e 7-2 
Mixed-cipher typessn.2 22.222 2hi cis See eee tee eek a cee ee oy S-la Sei 
Plaine oo) wen eo os bis cea ee oie ok eas eo sle pda deded Haewbaswa al et Gasket edi eectescaes 1-Sa i-3 
Plain component....c see ened Eee 8 Boe oe eet et Sede e ees hotel Soke hehe de Ges T-+4 7-2 
Plain, relation:-to° cipher soos. son ce cheese edbeeosouse bee ee cee Cecate eee et ceteEeoteueeay 7-3a 7-2 
Reciprocal Mee Satna! won betetd eK. 28 tatty le tiie vt aed ee wee Sea ee NS er ONS he Bet 7-6ea T3 
Reciprocal asinverse diphabets >... se Soe sc Ch cee ose bee ie eee eo ee ee et 7-8c T=35 
Scan Gardecl Doers ee a ad Ue one ae ha Oe I Rs ee eet 8 A Rt yah 74h T-2 
Anagramming: 


Column, 


Bes as 
Digraphs, expansion 
oie of, low, ne xe 


Tri graphs, NSO3 LS a See oe tee hte ee Peed Bacon tne case NPN fast apa era AN dtc arte Seg teh 


MoOwelecOnsSonantetatio. Ssace wate See cu ee be tev coe ect ie eee Sete es ete 
Analysis: 

Aperiodic ciphers Sarat api Linrdpnn iso eae hw ineet et aaah tasntn als malls tel suet aha attoh WA Date Wine ce Se IN cart pare 1-4) 

COGE: CHATS 2.104 coe wae SS Sik oh owls Sa Suisse Beater Bo ose ae Seer lease Sacclsae cues coeee oes 15-9a 

Digraphsinjapettodss cipiers=—.. wen nce le doo el eben. See bed kee te bee eee ae L4—de 

PourssqGarés-cipher svstéms.: 2. sus he ot opine Se ee gee eee sete es eee te lil-2a, l1-3e 

diorizontal two-squere. systems. oe vn ee hoe eee eee ses ole te weeded udev eee Seed Le Ll-oa 

Idiomorphs in aperiodic ciphers 14-69 

Interrupter letters in aperiodic cipher 14-Ta 

Tsologs in muitiliteral sy 9-12a 9 

Keying units in aperiodic ciphers. 14-5a 1 

Polygraphiec substitution ll-la 1 

Probable words in periodic ciphers 13-7e 1 

Stacked evcles in aperiodic c eee i4-6a 14—! 

Superimposed text i 14-6ce al4-10 

Svilabarv spetling in matrix codes. 15-110/2) 15-11 

Sylabary squares. 15-10a 15-9 

Symmetry of position in aperiodic ciphers._..._......_-..--.2-- 2-2 ieee eee ee eee id-te la-+ 

Text beginnings in aperiodic ciphers._._..._...-.._1-__----------------- eee Cee ere ee 14-80 14-14 

Vertical two-squate. 222.20. -ee cone. geo ele eave. othe diet do ete we ook be eee eeas eee 11-6e Ll-lt 

Vowel-consonant relationships. __._-.._.......---.----------- +--+ eee eee eR Slate Otani te 8-ita 8-13 

Aperiodic polvalphabetic substitution_......._..._..._--._.-..-..----.-----.---------- Saceh okals 1-126(2) (d) 1-6 
Aperiodic ciphers: 

Analysis. _.2__ Sea hs fos cise Sec ene tye Sera eee Si ee Dis eee She ae eee sees : 14-6c 14-10 
IdiGmorphs 22202 33223. cc se, se nak dost bales wl eae ee eo loa a et Me ak bets a 14-68 14-10 
Intermipter letverss e222. Je cn eo ee a Se ee a Ge ee eo 14-7a 14-12 
ACOV ID UNI tS tora he re A AS eta late OVENS Ls AS ah dae) ote ita a at a i4-5a 14-§ 
Stacked cycles... 322 ee rece tea es as ache tbe oe ea eben eho e eh Get oietnde 14-6a 14-9 
Superimposed text. oo doe hai ies Sota Sow eeees bee oe Se oe ete eh ees 14-6¢ 14-10 
‘Pext DERN dings. — 228 Sieh eo poe ake eke see hl wee balen Je oat Sy 14-8a 14-14 

Arbitrary group encipherment_..-.._.. 02 ee ee ne ee ee eee ee 14-3d 14-5 


Aperiodic ciphers—Continued Paragraph Page 
Cipher sequence, juxtaposition........-..------------------+--------- +--+ +e ee -  eee- 14-42 14-4 
Cryptographic classifications... ..2se2...5. nese eee eden oe ee ee bese bcee eset ee ete l4~lc 14-1 
Principle of aperiodicity l4-la l4-] 
Produced: Z 

Arbitrary group encipherment =<. 4s 2 Soc ce tweedy seh eee oid eee Je ee i4-55 14-3 
Successive word encipherment._..--.--_---------------------------------------------- l4-2c 14-1 
Variablé-groupencipherment:.2 ios. cco cee goss ood gow dcee nee oes eae edasedon sade 43a 14-2 
Repetition: 
Partial periodic. 14-3¢ -3 
True periodic... 14-38 -3 
Suppression of periodicity 14-15 4-i 
2-2 2H! 
l-Lle 1-6 
Biliteral substitution: 
Digraphic.I:C. tests 2.22 .ncsuie keegan ick sen deseo sees bleed set edad eshee cee beet le 9-75 a5 
Digraphic Phi test aa 9-74 Qa4 
Tdentincation soo 220 24 ole cede ee ote ee eS eB ee se Ue ote ee ee 9—5e 9-7 
Methodsicsso2.cs8hies cite ti fiie ohe k bole eee eet ee ee et eek to de ece toed es 9-3a:2° o> 
Process a> GS-2 


Biliteral systems: 
NIACIN GIMENSIONS e's. dade a suowas oa eee laet ee eee c ot ook Sed ee eae wee a Gee oh eased ee een e 
R@COVERV Ol IMAUTIX: .- nes l er ee we bced cx slacietueia lene see iua set aess owete Rika en eed 

Blanks, use of. in monomeé-dinome 

Book codes, classification of 


x3 


Categories of placement in Playfair ciphers___......_._-_-.--.--------------+-++----------------- 

Causal repetitions in periodic polvalphabetic systems_..............-_------------------- eee 

Chaining equivalent values in multiliteral systems_.......-_.--.-.-------------------------- eee 

Characteristies: _ 
Four-square digraphie svstems___..---------- ee e ee  ee e eeeeeeeeee : -+ 
Mixed alphabets ins periodic ciphers. ..4.c2205 2. Sete edt ote tin bwcbeetoe cere tebe bees heels iam -" 
Monoalphabetic substitution. .___......0.22-- 2-2 eee eee eee v- T- 


Poiyalphabetic: 


Monoalpnabeticitves. 22 cats ee ee ek eh dee kee oot cowie bee ee 
DUDSUIPULION aces cA Sb hee ts Ghent see ee Soe os eee t neha ea ek ee cel 


Trinomic systems. ......--.---_----- 22 --e eeeeeeee 

Uniliteral frequency distributions. < o.oo Sees See oe ocho clae sind whee feeerece te becse eos us 

Cipher alphabets: 
Alphabetic sequence 


Cemponents___.. fae Mo eee teas fo heels ede ieee ee vee ths OSA eh nY we shee ie 
Configurations of, polyalphabetic 2- 
Decimation: of; mixédv.ck oo ec ec Se SS ee i ee hc eee a ote ts ee ae 8-44, G6 WE Ses 
Derivedfrom, polyalphabetieu sac wav. cose ote eto. actos ei este ee ee -tat: 12-3 
Identification: van > ; 


2-5 

independent; -poivalphabeticw. si veces hate we ee ek fae et i a ed a: w-5 
WKes-word mixed. 2.32 sooo shoo 2.58 fae sehen Soke ATS oe ee eho Soi ao oe EE os 8 s-1 
Mixéd sc. so Oe end wee ce, Seine gis bees Soe eae ace grates he Tote 7-2 
Patternssin- transposition mixed2<cc..208 oul Jen Po ces Oe ba wee Sa See bee decent Jandel oowaee 8-34 S-2 
Piain-COmponen te 2.x. ot ew ecto Be Belt le Ea ete rated ei tape na! Sete wets 55. sk T-2 
Polyalphabetic configurations }2-4 
Randomly mixed:2..2 2s. behets oe es sie ee a ee ee Bee s-1 
Reciprocal keyword mixed. - = 
7-2, S-i 


Relationship cipher to plain 


Index 9 


Cipher alphabets—-Continued Paragraph Page 
Standardscst soe ctl ole even Shea ele ee ene oie ee ee oh Ut 7-48 7-2 
Transposition: mixed. <0). su. oa occ lebcecs a reseed teste oie Uoeede set sth ecceusbe te edese 8~3a &s-2 
Type.components.of mixedics. 2 ..22scce eevee se Saco susan eee ee ieee dese jesusecucicn 8-la. 8-16 a1 
Unrelated polvalphabeti¢u< 2. o1.cscccet a et once bel eee cece te tee tk See Gere acest 12-4a(1) 12-3 

Cipher dévicesoo ssn owe svi eye ce reteset ete lest oe ss cep teeth tas Geese ees Saes & 1-9a 1-3 

Cipher equivalents, placement of, in solution of four-square ciphers.......---..--------%--------2-- 11~3a(2) Ll-4 

Cipher: machines 2.0.22 ee te See oee a aie See fee ee eee ee eee als 1-9a 1-3 

Cipher sequence, juxtaposition of, in 1 aperiodic CIDNeTS Salis o eee eee eee a et a teas 14-4c(2) l4-4 

Cipher systems: : 

Four-square, identification. ._.....-.---.---------------------------+-+---- +--+ +--+ +--+ -- 11-2a il-l 
Playfair, analysts—. etn tears odes ea Shane ied BR ee oe hea eee Ree a die act ers Sane ahd ll-7a {i-14 
Two-square; identifications..o.2. 25.22 fos caine eso ee bide el eedeeese Ss coue Se See Se ee ees: li-4a 11-8 

Cipher tables. 2-2 fchee tc cu dsb dc stadidereeet a seee sch edee ceric setoceetctoslensdeics ce esi sss 1-9a 1-3 

Cipher to plain: ? 

Equivalencies in syllabary codes..__.......------------------- +2 - eee ene eee 5-10e 1-10 
Ratios in monome-dinome systems__._....-..------------------------------ ee eee 9-l5a 39-18 
Relationship: 


Ciphersalphabetsvcc.022 24 2secuedecauewiwesgt etareetet Gs ds ite eensy tee cog cees Seeteee 
pher’a 


Classification of transposition systems 
Code charts: 


AMBIVSISis Sic o les st os eee ears 
Classifcationv. = 22. tee ete ee ce eae el pate ae ene tA aint ee ie OER ae dade es 
Code systems: 
AdVanta tess 2s o2s20 veh. Sess ou eh cto foc eae Soe eee eee eo se ete tate ee See 14-6 
Anelysis: 
Code charts ..2.u6 or vecens dese ent eee eetrered tien see dieses eel oe eeeeess Sa 
SUUsOaEy Squares 5 Sot koh oe st erin PS Ue elt he al ao ge Sea 13-10e 
MOOK. COdSS acne ert es AT ae tet Ee bie ttle! ah ed cn ab tat ois ae Db el te oe ae 15-16 
ClaSsIf Cation .22 a. veh oe neon eek eu ene ne nee oan oe oud oe te Se owe ee ie 95 
COGC-CHATUS fe 8 ek Rete See ie nd Aa Me aD pen sake ate ena es BO aed nt ay ap eee Seen ee ae 2e 
ENC bered sCOGES is Oe anne cnk, ch Ss ees a sc eae cawed wucowMelase wees oe eae 3G 
PGENtINCATION ces tt eh COE ot herent ence raed en El. Sh eA ee SED kA el ant Dade ny Fig We Ta 
Matrix codes: ~~ 
Classification 
Identification 
Reconstruction SE iets ate Meee AP eat Set sent eh ay elt Sed Sen hans Se Ava doin tm ha Ae sm tte ae 


Open codes___/ 
Principles of analysis 


Syllabarv codes) oc 20 owners stor Se sce ap ca atelwunie soee mae oeel eee Dees at See ceesee : 
“lWOsPart. COGS fitness ont swe ee asl LAT ho ee eaten otal ek ore is 8 15-15(2) 
Columnar keved transposition._.......-..-.------- 222 -- eee eee eee 3-lle 
Columnar order: 7 
In two-square matrices... eee eee pear 11-~da(3) 
Coiumns: 
Association in @nagrammings2. 220s ue Vee ee ee ew ek ee ec ee eee £-8c aot 
Tsolation of, in, ciphertext. co... 2. ec echac eck cence bcoden ce etecieSebedcedescetbucstasece +110(5) ot ee 
Juxtaposition of, in matrix recovery_..._..__.._...--.------.----- Doo cane ee ete 4~10d 3-7 
imitations of; lengthu.n..2 225 ce el es a a atl 5 oe ON eee +10c 4-6 
Minimum-maximumength.........--2-2 2 eee eee eee ee eee eee intone feta NP 4-10d 1-7 
Communications:-—- ~ * . 
Intelligence (COMIN DT). sic ocoue ici koto oe Dances ceded sear ee ee ee See 2-4 252 
Intercept.operations:.\.scc0 aes en toe eee Soe s seteettiece aduaoenwewoge Oeeseass 2-4a(1) (a) 2-2 
Meéans<of;:definitionie. c2ccsee iow ew de ed ee Be es Se ees eee s 1-55 1-2 
Secret origins Obese chow sees Jodie seo cet eee ee ce Sues Cee Let doce SuceeSceeeees -66 1-2 
Completing the plain component._......__----_------- eee ee eee ee ee eee eee eee 7-12a, 7-12c 7-9, 7-10 
In periodic ciphers. ._._....--- 22 eee ee eee eee ee ee eee eee eee ee eames atte 13-4a 13-3 
Computation of digraphic I.C. test__...._..------ 2 eee ee eee ee eee 9-Te 9-6 
Condensed table of repetitions, use of : S-13d 8-12 
Consonant line in vowel-consonant determination. _.____.-.-.-----------------eee ee eee eee eee Siva er 
Constant interval polyalphabetiec periodicity.............-...--------------- eee ee eee eee eee 12-9a 12-7 


SONFIDENTIAL— Index 3 


Construction of grilles: 


imple 


Cryptanalysis: 


Definition. 0506 0 oS ee ule et sind seth steal awadtad Re RN tana tok 1-4 
Determination-of language... 024 eee ce bese ee eeeetedled oc Getetssacueescasccee ee - 2-5a 
Fundamental:operations.. 02 sof. eccuwen tel veo ees Bobet ocr ee eae sca ees bees ene eee 2-45 
General system determination 2-ba 
2-9 
Cryptanalyst, see definitions. 
Cryptanalytics, see definitions. 
Crvptograms, see definitions. 
Cryptographer, see definitions. 
Cryptograpnic: 
Classification of.aperiodic clphessu. cs vers sel Siok es Sasha at bee es ee oe ote ee Soa Se l4-le 
Systems: 
Application Dowie owwis tek ethene Dec acte eee ec leeectGheceaeeys eet vee caaeoew es 2-id 
IXDIOWME EON Joe tae sot oS ie ee, | Ste as hl nce et oe a eed Set Seen 2-5 
PASMIDI CYS betes No cfin pene ato Re te niet mrs Seleo acter a altar S Seaycta ae ote hea uta eens tei 
General_ 
apidity 
Reliability 
Requirements -. 
Security 


Soundness __ 


Cryptography, see aeseaaas 
Cryptology, see definitio = 
Cyclic permutations of Playfair CID DEM Mates rss hte Ne aloe es Bast ME Hele De ee ay Li-9a 
Crelic phenomena in polvaiphabetic substitution: 
PRUCCU Eno hea ee wash tbe Stee be ema Get dha kieSie cabot oon helen den tcvader ede Minto ane 12-5 
12-34 
12-34 
Decimation: 
Determination of ingerva 
Mixed cipher alphabets... 50ccc2202.52 522 ces cunee aie eee seed oe ES ete eee coe teas 
Mixed sequences: 
Femword based. ict his eit eet i eee ets oh ie Mae ed on et S-9b 
Recovers 2 4 a foe ee a oes lone oe at te ee ee oe ee oie S-9a 
Deciphenne-alphabetecec 6 ees Pw he eso kol ts cere tie Bebb Ate tee eet to eee 7-70 
Decrypt, see definitions. 
Decucea Values; susstituting tore fo ett ee ee ee at oe Se ee ee See 8-154 
Definitions: 
Addrésseg A474 oh elie Se eh et eee ns a had te ee tae Oe De eae Si ee oe 
CIivptanal ysis. cos os.22 tase baa ete hie ehcoeol canes hes athe be ale deed ees ou demese < 
Cryptography. 722 J .cheatetess Ea 
Cry ptologyis~ oo..oss0seesa eens fA D the 3% Maal MeN adie ab A Mae ae ea at Wt babe Wie hee Reet ten ott 
Externals 2 oc) ees Sek ee eee eels de Sacccey fee delete c eedueeet oo esodseee pede ce 1-39 
ions 1-5) 
i~5c 
1-SA 
1-e 
1-Sa 
1-5d 
Derived polyalphabeti¢ ‘tipher alphabets+<222230:2 cet ucts os select ude wetccaese seeke o3 Siete cas 12-4a¢2) 
Determination: 
General system in cryptanalysi cee 2-6 
Interval in decimation of mixed sequences_.........-.-...---------------------+--- eee 8-9b( 4) 
Matches in multiliteral systems__......_...-. 22200 - ee ee eee eee ee 9~10¢ 
Diagonal encipherment, Playfair ciphers_..........._._------------ 2 ---eeeeeeee eee eee 11-76(3) 


Index 4 CONFIDENTIAL 


1 
2 
= 
Rs 
) 


Digraphic: 


Blank:expectation testo. 222s whee Sele eee sete aed Ae eee eet peepee lke ee eee eee 
Distribution of multiliteral systems.........------.-------------------------.---------- ee 
1C.-test; computation... es otra seco ee doe eee ee ioc eb oe eee See hee 
Idiomorphs in four-square systems.--___--.--.-------------------------+----- eee ee 


Substitution: 
Four-square matrix._._._- Pai CUNO ta als Fan EA elk ee esata RAND Dhaene cn eee ott pal 
Plavtaitsieset ose poche ta seats ee Ss ees Ae eG Se Seas ei a rae tl cette Dd doe 
Two-square matrix 
With matrinésT_ 2 7 

Systetis) identification. 2204 os ble od ees Skee ee ee eketeen sensu beoeie os 

Digraphs: 
Bzpansion of, in anagramming.2.< 2.2 -scbos eles eee eee ee sec S ee eee Soe Sheed 
Identification of, in Playfair ciphers.........-.------------------------------------- ----- 
‘Wserof in anagramming. 222 eee ee te oe Se eG Shee dee a oe 
Reducing to: wniliteral terms... sss. ee ee ph ee de pee bee ee ee Go eee ete ice 
Dinomic distributions of multiliteral systems....._....------------------------+--.----------- . 
Direct transparencies in two-square systems___._-..--.------------+--------- eee eee ee 
Direct standard cipher alphabets, identification. ......--.---------------..----._.---_------+----- 
Direct symmetry of position: 
Implication. of,im periodic ‘ciphers... vos cu Leica lessee redee cece boats ee eekeeciet 2 
An periodic: ciphers: 2s ones ses ges tt oe eases oe ose en eee eee bbe tissec tesa 
In alphabet recovery. ..2 cn 2ote ols leus vole edee ete ee edi ecg tbs eee alk ete eee ee oe 
Disadvantages of multiliteral substitution........_..------------------------- eee ive avez, 
Diserimilent.c2,2oy ce Gsne gi pees Sosa seeetiee toe w dees tote ests ane oe eet dete aoa etek pecs d 
Disruption of columnar order in poivphase transposition. ...-..-.---------.---------------------- 
Distripution: 

Peliteralirequency ce. oun foe oe Se ee Oe et ed ou seemed 


Inspemodic-cipners.22 ich ec as seceh ese bce tealee usa se ves cee Sees e eee oul doet a eeet eae 


Dinomic, of mullite 
Frequency, variations 


Pi oe a 


Elimination on generatrices in periodic ciphers........-..--------------------------------------- 
Enciphered codes oo ogo sss. et col oseke ee docen oles ek aoe ee evceede olde Sle tees sedan 
Enciphered codes; tlassifiction code systems__.._.....-_..-.----------------- eee eee eee ee 
' Encipherment 5 a 


Letter position limitations... 5 ...-..4.-2 22-0 ces ccs ele wee be possee st cee cee eee lees 
Reciprocal. Gos ce face ee ee Ne de Pepe ee eS 
Reversibles. 07 ono Se ad testines eatiok daw etc sa bet se se ohe ceo w se 
Enciphering alphabet 
Encipherment, Polygraphiec: 
Charact@risticsie. 462232 a cece se oat bluse actos eusasea eee tate ese oostse mes 


11-76(1) 


©. 


me 
PP 
rap 


ode 
' 


{ 


vom od 
an rere 
“Vide Ler ne 


aphic—Continued = Paragraph Page 

aS oo ted ee oo | 

Wariant forms:2-0s2.c20 Scc0ce edo ou ou thks nee tie Sue eed eve heee ewes Sebeeee eee aas 10-42 10-4 
Fincoded! ciphersisoo2-s3iee5 coer eee ddived wees elec eee se essechovetseerdesucatigsiaecocean ss 1-9¢ 1-4 
Encrypt, see definitions. ~ 
English uniliteral frequency GiStMiBUtlOne sc ert ee te ke th AE he ht ho ho at SERA te at 2-116 2-5 
Equivalencies, cipher to plain, in syllabary codes_-..._.....-_----_------------------------------- 15-10¢ (fS=10 
Equivalent values: . 

By Chaining saca.1s 22 22a Sac C et eet et atas chee odes Oo dasse a eee oe ee enna 


jteral systems 


Se f ernie 
Expansion of digraphs in anagrammings 6 oo easitseads seed ons e tock eeeecee auc eu ds oe es 
pxpettation test; digraphic, blanks: 52.22 vi eee ee eee eee ee Sele See ede et eee 
Exploitation‘cf cryptographicsystems,. 0-225 os-2s ck asl ec es case ees se cbwee sede oe sess seb. cek 
External evclic phenomena in polyalphacetic systems__._..--------------------------------------- 


Externals, see definitions. 


Fixed polyslphabetic periodicity 
Tlexibility of crvptographic svstems.._........-..-------------- +e eee eee eee 
Flexible polvalphabetie periodicity. ......-.--_----------------- ao ee ee ee 
Four-square matrix, digraphic suostit: 
Four-square cipher systems: 
ANalySis 2. 1c oe eee Leek eect eestor lace ates J etdueee ee cee siweeicec ses yeteldesGeaee 11-22, l1-3e ii-1. ti-4 
Digraphic: = 
Tdiomoro hss sc Sede soso ose ee ere eres sateen ee ee hs ay 11-3d 
Patterns 2. oC sos 42 bdes o seb eee hoe see ete eee eed Soe oa cece Gee etees co sce 1i-2d 
Tdentiication..c cess se cake etste ab hawaes eon 8 11-25 
Matrix recovery. Ll-Se 
ny Pony 


Placement of cipher 


Word assumptions. +2222. ea esol veya ot Shee ced cote eee ct ete eee ee 
Frequency distribution: 

Normal theoretical deviations.....__....-.--.-.-_----------------- eee ee eee eee 2-136 2-9 

Profile in multiliteral systems : ee 9-106 9-10 

DTHiteral. conciseness wet eb se cdentt hoo see oid team eee woes wee see doe see 8-134 S-11 

Variations...) otc a oc ol ou oe Soe abuses ance ce ene eee wel a An ee 2-13¢ 2-3 
Fundamental operations of cryptanaly3is_.......-.-.-.-.--------------------- eee eee 2-46 2-3 
General: 

Cryptographic.svstem=...2s52iceo isu ao sk deh eons Sete Peete rete eels sees oe 


Generatrices, periodic ciphers: 
Blimunation 22.0.2. ese cece ces ceh tobe ct chee eee ac ateetcte to oeeeectelae eee Gee 
Logarithmic test. 
Selection =. 2- eos esenesce deco sn cove cee So ee ace 
Geometric design of transposition matrices 
Grille: 


Transposition 


Index 6 


Horizontal: 


Identification: 


Intercept operations... .-- 
Interrupter letters, analysis of, in aperiodie ciphers...................----------+-+---2----------- 


Two-square matrix, encipherment___.......-..---..---------------------------#-+--+--------- 
Two-square matrix, analysis_...-..---.------- on 


= 


Aperiodic cipher, numerically keyed 14-4a 
Biliteral substitution. ..222200 200 ee eee eee eee 9-6a 
Cipher alphabets: 

Direct standard.....2 2 eee eee eee eee eee 2-12¢c 

Periodic... 22-2 ee ee eee 13-id, 138-l2a 

Reversed standard. ___._.._-_ el ee ee 2-12d 
Code systems, matrix......... 22-222 2 ee eee eee eee 1a-Ta 
Digraphs, Playfair ciphers...............-.---------------------------- eee eee Li-7d 
Digraphic svstems___..2 2.02 ee ee ee ee eee eee 10-Sa 
Four-square matrix cipher svstems........_.....--------------------------- +e eee eee Li-2a. 
Incompletely filled matrices...........2..-.---------------- 2 eee eee eee eee ee ee eee 4-3 
Matrix codes through code groups......._....__..--------------- 2 eee eee eee 15-7b 
Monoaiphabetic substitution. _....2..2. 2. Lee eee ee ee ne ee eee Tole eee 2-124 
Monoalphabetic mixed substitution._.__.._______----------- ene ee eee eee eee eee eee S$-10a 
Monome-dinome systems....._._..-..-------- ee ee ee ee eee Lae eee 9-15a 
Nonmonoalphabetic substitucion : _ 2-126 

6 


systems... 22 ee ee ee ee ee ee ee ee eee 


Two-saquare mat®ix cipher systems t 
Uniliteral substitution. .....__.__- 7 
Idiomorphism in apertodic ciphers, anaivsis........._..-----.--.------------------ eee eee ee - Ld—+te 

Idiomorphs: 
Analysis of, in aperiodic ciphers.........--------------- +--+ +--+ +--+ 222-22 eee ---------- 14-66 
Appearance of, in Plavfair ciphers...._..........-----.---------------- eee eee eee 1-Sa 
Four-square digraphic..._......._....-...------------------e ee eee eee e 11-3d 
Word patterns derived.._...... 222 ee eee eee eee eee S-15e 
Incompletely filled matrices: 
Identification..._._....-2 0 ee ee ee eee eee 4-36 
Recovery... ee ee eee eee ne 4-106 
Independent or unreiated polyaiphabetic cipher alphabets__.....-....--.------------------------- 12-4a( 1) 
Index of coincidence, use of, in: . 
Monoalphabetie mixed substitution.......... 22 2.0.0-000.0.0..0. 0220-2 eee ee eee eee eee S-1le 
Polyalphabetic substitution.._...0.0 0.0202 eee eee eee eee ee 12-ila 


Inscription routes: 


so iii Matrix... eee prsee ing 


g-4a(1)(a) 


_ ° i4-Ta 


Invisible or unintelligible writing.......2....___- 1-6d 
Isologous segments in multiliteral systems 9-12¢ 
Tsologs, analysis of, in multiliteral systems..._...__..----..2 2.0.22. - eee eee eee ee eee eee 9-12a 
Isomorphic patterns-in multiliteral systems...._..__._.-------- Lb Dee eee eee eee nee ee 9-lla 
Juxtaposition: 
Cipher alphabets, periodic ciphers...__..... 202-2 ee ee ee eee ee eee 13-134 
Cipher sequences, aperiodic ciphers___.._.._..._-_.-----------.-- eee eee ee ee eee eee 14~4c(2) 
Columns in matrix recovery.__..._.._.-_______-_--~-------------- eee ee eee eee eee eee ee 4-104 


Vo be be 
t 
Orme 


j- 
es 


pe] ow 

fon J 

rere rer 
ve Oe EOE BO) 


po) 
{ 

- 

to 


Index 7 


Key: 
Numerical, derivation 


Setection ofiitéeraliic.2cc05. Socso ce tdee ns sans CEOS esS est chee eee See ie ee sees ee 
Specific Aten sesce sees Saas 42s ee soe tens See een ea ece ts oe SURE eh Sees 8 
RGCOVEP aio 2 s secre ete teeth ae ie ee sa cece ease see oo eee Some ete cine oe ok 
Transposition, recovery. s. susp soie ens owes eee esses sie we ee te eee cee besos sen ee 


Transposition mixed sequence...._--..-.------ 2-22 - eee ee eee eee 
Keyed columnar transposition: — “ 

Operation 

Securitye: 2 coda Sowa es eaten cee et oo dete fo cee louse s i eee eee see 

Variations ee 
Keying units, analvsis of, in aperiodic cipher... _...--.---.--------------------------- a ae 
Keyword based decimation, mixed sequence.__._.-._-_-.-------------------+---------- +--+ -- ++ - 
Keyword mixed: 

Cipher alphabets: reciprocal... 2.2 ces yesh ce cda vce etseeescctedecsdee ccc ce seculosesee el cee 

Sequence; recovery ssw cba oss eee en Se ee eee Se eee et ce see eee es cee te sae sooes 
Lambda (blank): 

ERpeCtAtION test] 2 seo ee ee io ee eet eee eee SE St ee wooo eS 

Monoaiphabetic mixed substitution, use__.......----------- 2 eee ee eee 
Language determination in cryptanalysiseu 2 o.oo eos Meee wa le pe Oc eeeu es see eS eeed ewes 
Latent cyclic phenomena in polysiphabetie systems..._.----.----------------------------------- 
Letters: 

Anagramming ee ead 

Classification: of periodic ciphers... 225.cc ct ede ede cols et eet see eee Ren cee coe aed Beas 

Positional limitations of lezters: 

Four-square ciphers. .cce aca tee ete ee oe ee cs eee sis ee eee ee ced 
Plaviair ciphers si ..2 ciwscosd ase do showuies sede reeset ees ie eee ces ee eo Fi sed Secs 

Literalskev-selecticnuc 229.2422 sc. stedenwacclods Seb eeietd «ee .wbes obese cee ledeee wes Sehees tee 
Logarithmic test for generatrix selection in periodic ciphers_._.._--------------------------------- 
Leawecerm Security's eccheisae sawn oa tee eee aie ee stems nctwete beet sews iidecetad 
Machine:tiohér. 2.0540 Ve Meine ee tee obioa te ce we ten tee eee ee Eh te oe eeton denis 
Match determination in muitiliteral 
wiatchine principles Of ik. periGdice-cip pers. c2o52. 6562 be heen ee eens eteceee. bene Se 
Mfatching variants by frequency in multiliteral systems......---..--------------2-------- eee 
Matrices: “ 


Dimensions: 
Biliteralisystémsn:. 22-22 2h Sel specs Goede eat ca eee bles See cau week ations bas Seem 


ransposition system 
Geometric:design 2o222s 20d. cscbeswde a cete ena lhe etadeeees eos eduketeeuscowtdteeeeSecuee 
Horizontal two-square systems. 
Identification of incompietely filed... 2.2000. ee ee ee eee 
Juxtabosition of colimnss. on ts Qe eu ee Sales te ee Saws ore ete eee 
Recovery of, in: 
Biliteralbaystemse ac 2s on ete: Sete Men owed ec el es bo Selene eee lo dete aesanseods 
Four-square systems 
Incompleteiy filled--.._.--.-... 22. 
Two-esquare systems... 2c obs ics nds ecadaessoacecscesespeshone Seeceecaus 


Ftical two-square systems. ..---. 8 ee eee 
Matrix codes: 
Code systems: 
ClassifGation cis tac fe. eh tot ft Sie ot AC ahh ett it INS Nt 
Identifications 22s 2 wn teeta od to oe att en ss coho teusdece oleatoouvesdotwasuekce ss 
Reconstructiony os is2 coe nddor a fescskce decd owaschadelawee pacouwcuslos Sandee idewe seh sacs 
Means of communications, see definitions. 
Message: 
Center, see definitions. 
Text, see definitions. 


Inde 8 _CONFIBDENTIAL 


ws 
\ 


who Hw 
j 


t 
ion ee ied BOP EE?) 


— 


Paragraph 
Military terminology as stereotypes.._......--_.-------------------------- eee eee 4-12a 
Minimum-maximum column length..._....-.-_...-----------+----+---------- +e eee 4-10d 
Mixed alphabets, characteristics of, periodic cipher.....-------------------------._----2--------- 13-9a 
Mixed cipher alphabet: 
Sequences: ; ; 
Decimation ls .cocese,c cen Sales selec ote see Blea eee te A 8-4a 
Keyword mixed: 200.2 ee cet eeeg cee Shee saet ks Ee een iS Bom tia rio Renee eet, temp 8-2a 
Randomily mixed. 20. c2c5cseowec' so Le Sit ecdlae Se nes cceee bite e ede eee ; S-le 
Transposition mixed__....--_--------- 2-2 eee eee eee ee eee $-3a 
Ty pes ois's wees ee kk Sen kde cn cee Sdseccedi ese etascele toreews sce 7-4a, 8-la, 8-16 
Monoalphabetic substitution: aa 
Characteristits 22.0 2sck oe ono loi ois eee ba os Bae ees So ides Seeing bes. cee tees ese T-le 
Identification. 292 ose se aes celeste bos eis oie ae Sse Soe Leen Se PSs ese Sek 2-126 
Methods of solutions 6 o0 5 jase eet ath te le a ol nt Ad ee Oe Al a es oth fe Pk 7-Aa 
Systems: i024 s2uco222 fest fe ecveneisetce eee aoe a eee oe ed sees g Lateiek 1-126(1) 
Monoalphabetic substitution, mixed cipher alphabets: 
Identification==" 22-2224 to ee ee bee Mee eee ee ee al ude s amie se Rous 8-10a 
Endexof coincidénté..-.eenJoc evens oie okeenewne eb ates eee tsee de ec ieeces Settee S-ile 
Lambda test lla 
Phi test.._.- 11b 


{Lonome-dinome-trinome-systems: 
Characteristics Gfo..2< 2.03 ee ei ee eo ee eh edel Sed the oboe uel eee bode de ee ees BS 
Solution of _- 


Aiultiliteral substitution: 
AMBIVSIS: 22.2 cedcoetendioten Seo ah ok ose crane Bee dds ct Sa eetee owes acts Hr Se see 
Chaining equivalent vaities: ...2o.cccuu Soe eee lee dees ewe det cee ce eee beet ess 
Classi®eationa<3 4.2. sence Seca tet eke t ouch dias ctetiwe oe tee ede ee es 
Determination of match._.__._...-_--.------------------ ph Acpt AL Dy oS ae eae 
Dinomic distributions: 2 s0.es<.4 soe deen ee Seek ceeeese eee tees setae ewe Lost ae Seen sed 
Disadvantages 28552. ore cecheus bode bee Seach eee ee veaee Mee eee ee eceee edn ee sk ebe gees ds 
Equivalentiwaltessc.200 sent ane etrccee ete eee ee Ol te een ser ek One Steer eceue etc. S 
Frequency EOD ese 2 Rt ti hata A Mie nS Wh Sek, lee pha Ro Mains cent Bate fae oe 
Tsologs; -anglVsise. cocci oe ee eke ese ab te cebu Soe ee ee eee Usk oa 
Isologoussegmentss sven. week ci sce cessed cece ade ne sees eee eke ale dane ce eee estes 
ISOMOPpMic. patterns... vec. steed ew ele ee Soe SER eek wee eG et ent So eee skate ei 
Niateh.determina tion s-5,204 2026 to oe ema s oe oi ese oe ee es Se tee 
Matching variants: br frequency <.2. 04 .ace ec cee tee sede ee ieee oes Jeeebe ewes e rede 
BOCUTtV oo h2 Ae ese cee eh ie ees oo Sees Me oe ase SU ete eis els es 
SUStOMS 5 cw a aie Sida cee cahe te dee et See teeketwsleteen ede ceded ees Stk Se 

Multinomic systems: 

Classification. 2 2 eee eee i Bo Boe See ee see eee Ss! Jn eee ls e eee ese 
Columnar numeric: 
Analysis 


Ls 


; sine cietiat i ta ee eee 
Nonmonoalphabetic substitution, identification. .._.._......-..--_..-_..---..-------------------- 
Nonreciprocal tables, polygraphic substitution_........__.__.-.-. Vseee Vien es shedaiewod venus Sedels 
Normal deviation of-frequency distributions..__............---.--------_------------ tbe sie etstts 
Numeric variations of polygraphic encipherment_..._......-.-.-.------------+----------- peer een 
Numerical key, derivation of..._.......-... 2-022 2 eee eee 
Numerical key in columnar transposition..............--.-.---------------------------2-------- 


Operation: 7 7 , 


Polyalphabetic substitution...........0-0 2-2-2000 ee eee ee en ee ee eee 
Simplegrilles.2 ows se sedate Soe cetee cote uk wenlea te boat ae eek ot woes Jet de ees heoeee Oo 
‘Transposition: systemso oc schlock ede te ce eee ce ce be ot te lees ote ece ease 
Originator, see definitions, 
Origins of secret communications...__.._..2-0 oe ee eee eee 


Index 9 


Partial periodic repetition in aperiodic ciphers....-.--._-------------_-------------------+-------- 
Patterns in transposition, mixed cipher alphabets. _.-..-.-.-.------------------------------------ 


Period 


Periodic polyalphabetic systems: F - 
Accidental repeats......-.--..-- 2 ------- een eon en ene en en nn nn ee ne ee ee ees 12-7a 
Analysis: os ef 

Factors : - 13-116 
Probable words 13-7a, 13-Sa 
Causal repetitions: 12-7a 
Cipher values 2-64(3) 
Completing the plain component.....--..-----------~------------ een ee ee eee ee eee 13—4a 
Determination of cipher alphabet..-..-._._-..----------------------------- 13-1ce, 13-10a, 138-1ld, 138-134 
Direct. svmimetry of position... 2 2 secs occ see eee eee eee bol ccs ece eee ekacsecaus 13-10a 
Pactor analysis... 20 oe. CussGedwade soe ee ees ade hee siack a be oe ee peace ee ale eee 13-11d 
Generatrix: 
Elimination 13-56 
Seiection....-------. - 13-5a 
Tdentincationey: woede etn tee seth Cee eb ete ee pede Shi 2 te ee ee eee 12-6c 
Juxtaposed sequenc 13-134 
Letter classificat 13-12d 
Logarithmic test 13-6a 
NEBUCHING 35 ote ho a ee ei ee Se et ee ee pe tee let i5-19e 
Matrix recovery 1o-i3¢ 
Period Getrerm ington... ot OE hse Sate eel ok CO eet Mitel Ne nem chen Da teeth EE 12-se:1) 
Repeating key 12-5a 
Substitution. .....- i-120) 2) +a) 
riliterai frequency tribution. 1$-ile 
Uniliteral terms as special solutions............-.----.------------------.------- Phat Cd asou,s id-ise 

Periodicity: - 

Constant interval... ..00.-2--cee cau nnn eunne etch Bune See seteCeke eee eet geet pote 12-9@ 

ug bere Steere eri dle nhs Sd at ete eat States oe ee ee S ape 12-Se 
Fi 49 cost Scho a5 12-38-13 
PieSiblesis. deus deGeeS Sadat tn cvicecest Meclae noc S Ase esiaca hose eee dete eee mean eee awleee 12-34 2 
Progressive KEV ss Soset uv oeare ee eed eee dao So eee eke ee cei ook ee Sec tee 12-3¢'2) 
Repeating Kev: noackiae ee ee ek a ne te at ed oats ie ede aie weed 12-3¢ [3 
Suppression: of, in-aperiodicjcinhers. 0+ 2. ovseo cee ioe bea teehee Ble we Se ee 14-14 

Phi test: = 
DISTR D AIC e222 e283 ee Gores SoG ee Ie See DOLE Set ee cee Roe etane ed eooe ee eee S F 1G-Te 

y 


EEplanagtiOnnc. 2. 22d aceon vue aoa ecb ees eee dacs 


Monoaipnahetic supstitution__.......-2- 2 ee eee eee 


ge x edo ctiee Meee tents ates ae eh ttt kA MA OU EE oh i EN i Mogi andy ae a ahah ain cee ee Men RAP eee ie Saat 2-15h 
Variant form, use... _.- RTS Fn ee ots Sih tay ty ye Sean ah nn ee oN ee, Say aes Se 12-i4a 
10-3a 


hy 
i 
“ 
4 
e. 
“4 
Q; 
ao 
oe 
aD 
é 


Placements, categories of, in 


Placement of cipher eauivalents in four-square system_.__.......-.. Li=3¢ 2} 
Plain: 

Al phabetss iMesh i OU ies Since pl Ais Zt Ro ees BAS 2 Se tee Te i-Sa 

Alphabet relation to cipher.._-2 2 eee 7-3ea 

ThORL PECOVCTVN ce te oe oe Sue esa es te ate gene A! SR pe os ee ee eae eh ae 2-Sa 
Piain component: 

Ciphervalpaah ete .5 Sev ee hae Ni Be ato Gila chee Me Sane ca ties cil T-4a 

Completion in periodic cfphers.._...._-- 2 eee eee = a ioedyonine ok 13-4a 
Plaintext: ae 

Recovery Ovcanserammin gos. cos 2 te is eo ee ie w eee ees eek ee tet Sead 

Recovery of, in Playfair ciphers._.._ 

2 EP nee sr Tes toad 


Playfair cipher: 
Appearance of idiomorphs_._.- 


Categories-of placement: 222025. 1. oe oS oe een wisn Bnetien ue Cer eco ee ebaccedbosesscdese 10-3d 
Diagonal encipherment_..________..._-.-------_ 2-2 ee ne nee ee ee ee eee eee eee 11-70(3) 
Identification of digraphs: 2... 022. ec duce te tee Seneca suse oearceceeenseece dee eeawies 11-7d 
Letter position limitations_.......---2--- ee eee en eee ee ee ene ee nee Ll-Te 


Index 10 SONFIDENTIAL— 


15-10 


13-6, 13-7 


. 
toe 
14 
He News. 


ts 
1 


Playfair cipher—Continued 


Matrix: Paragraph Page 
Cyclic permutations: 26.3355 2202 tosemee cack sect eens tesco cess reece ecole esoeus 11-9a 11-20 
Recovery secs teee sd lees cee ee kien sete e les Bee eee eee he 11-9a 11-20 

Plaintext values, recovery 11-8c 11-15 

Procedures: of analysiss..- 20 sce eo soe cee eet eeeeectecus sock deed pseu aaa ee cieced ‘11-8a 11-16 

Réciprocal: entipherment 2.0/2.0 so: See ve estou svewssodeisc lsc hseet eed tse semes ease te ce 11-70(1) 1i-14 

Reversible encipherment___._------------.-- usabemectecs Qu Wate ae netle sian Gtk ook elem ee 11-78(1) li-i4 

Systems =.2500 5-4 22sec ck tho cece eee OG liseeewicie De eecce saree Seles tues set eu eeeeees 1l-7a li-14 

Polyalphabetic: oo , 

Accidental repeats-in periodic systems.-___..-_.-----.------------------- ie Sndge eee Ss 12-Ta 12-5 

Aperiodic substittition 2.0020 22..02-s. 55 leee eb yp eidocel eek sues ce eee eek eee 1-120f2) (6 1-6 

Causal repetitions in periodic systems_..._..__._-----_..----.-.----------------------------- 12-7a 12-5 

Characteristics: mE 
Monoalphabetictt¥ <4 jose ea ee he ae eee ae eee Mat, nig 12-10a 12-8 
Substitution: 2.222520 ceosesie cece edie sbi ched ed ae betes cede See eee ke 12-15 12-1 

Cipber ‘values in. periodic-svstem 2204 Jo soees set celles. Pade eee eee tebiete gustetockesst 12-6a(3) [2-5 

Configurations of cipher alphabets........._....-_---.------------------- +--+ eee ee 2-4) }o-4 

Constant.interval in periodicity. .22...0cic.2co0ccb seb nn mec node tieSh none acer he ee aaaeeews Meeks 12-94 12-7 

Cyclic phenomena: 

POX CPM ar os ab Aout OAS nl SGD ie ast ae Ble Roel a at es Bee AM hE a ot hall eu fo BS 12-3d 12-5 
TSS G OTE are roe ane a a Pe et AO ee Carne ee Me Sl ete te Ne ea ee ei) tas 12-36 yess 
Patent. c.as oy Steet os Sth hk ee a oe ie Bn, Peete athe a Seite oes 3 aah, 12-35 12-5 

Derived cipher aiphabets i2-tai2) peas 

Determination of periodicit 12-Sea L2-s 

BSOECTEG TEPStItIONS...2 ee oe he ho San pnts Set eel etd neh de foes L2-Te {2-5 

External eyclic-phenomena 2 22258 jek eet oe dee ela a Neen wae See ere W tee se see 12-35 225 

Independent cipher alphabets_......-.-..--..------- nn ee ee ee eee eee ge eke [2-4ai 1) Lea 

Object Ghsthstitutione . i026 cole eee cos Soo heart tl eens dete aw Sooeylee eet eee 12-10 i 

Opersuion Of Substitusion. 223s cara oS oe a brew does betae w Role od Pe Ge See He oe ee cee iee es 12-2d 

Period determination in periodic syster 12-6a! 1) 

Substitution: 

APOMOGICs 2u 226 See cheat semi osce coe ou sos aemhee roach as cer soes ete lek Sees Sas 1-{25(2)(9) 
Periodic : 1-125( 2) (a) 
Types. __ 12-32 

Qurélaveditis ner anaes. oe ec ee ek Se oe Le ei eee bees et ew ew oe eee ee [2-tai 1) 

Use: 

Tniiexyof cointidence. 225200052 sacbed toa sclls od tates ck ces ie ese te theeed ee Se Ean erates 12-122 

PH veStu sk onc we eee eee ond een opheaceewee decane nt Deb cc eae eed st oewesendasetases I2-lle 

Phivtest, wariant formic. es A ot Pe ed hk I ted oi os hte oe j2-l4a 

Table:or expected: values< 2-3 os ee ke ie ha Se a 12-13 
Polygraphic substitution: 

AM GAVSIS ac sie: God Yaloe Sore eee Sethe tee odtetlat. soe se biioe Bete tent eae eueNnt 10-24. Li-la 10-1, Li-t 

Characteristics: of encipnerment.2. 20 -oscn tc et Gels ben tenuate eae ee ce Sew autos 10-56 10-45 

Cipher systems: 

Playiaite cost cones lwo Sob eet aes atl ks Ae a dete ik te dln 2 2 ll-Ta 11-14 
Tiwo-sQueres Josie ees ec sous So eevee tee eee oo enc Soe ds eee os Ban Baecaeee sae li-+ta 11-8 

Encipherment by variant forms_..___._.....-...._------------ eee eee eee 10~ta 10-4 

NECTNOGS tc, 3A oes ts oe Nec tO et ot ed nea ie ar dee haan coe eke Seem 10—2a ig-! 

Nonreciprocal tablens o.25 20 oo sce sole a oe oat. ee dence deh te oakelateee i ONS ae 10~2c 1G+2 

Numeric variant enciphermenty.¢o325 Joss i ash otlecwllcsdcckedades sec Ugebt ek acest peielve 10-4d “10-5 

Purpose iv. sede ae tk hs oes a en ee Badin eels Sond fel ote s Bee i0-le 10-1 

Reciprocal tables_..--.- ee ee ee ee eee 10-2). 10-2d 10-1, 10-3 

Recognition 10-5a 10-5 

ecurity...._.I0s7= eek cates Se eh ehh ee hea, or Staal a Sen hat wet date sae 10-26 10-2 
Solution -principlese. = ses0es Jobe ee od tee te coote dase eel ane e eeerhe Sa enon $ L1+1b ‘Lint 
Positional limitations in four-square systems__..._.___....__._------------------- eee ee eee ee eee . 11-36 Li-5 
Principle: — 
Analysis Of code .SyStéMss 356 25.02 ee tea fon cee ee eae oer be wet cee 2h 


Aperiodicity in aperiodic cipher_......-........--.-------------.--+-------------- Seelee east 


a 


e word in periodic cipher anaiysis__...___..._._..------------------- eee eee eet ee 


abl 


Prob 


Index 11 


Progressive key in special solutions: 
Same‘length message. 2.22225. 5 stein seein t Sake Skecse Geena seewes d 4-16 


Superimposed message 4-16 
Use of, to recover numeric key 4-18 
Radio-:direction findings - 240 eos See Lee scabies eo ee ee ee ee ee eee 3-4a(1) (ce) 2-2 
Radioingerprinting. 2.2.62 c22.050. n8ee Se sects Sle pees aeons See eet oe be aioe 2-4a(1)(d) 2-2 
Railfence cipher. 2002255 Sock wea dee se ceeeeet ols ece became sacec sei ad ecer eceeteee oe 3-Sf 3-5 
Randomly mixed cipher sequences. _-.._.- si RONEN ae Sed chee S18 at ono ee Mi ay ear GRRE Sel a ete aeaa ef B-lc s-1 
Ratios: ; 
Cipher to plain in.monome-dinome systems_._....--..-.------------------------------------ 9-15a 9-18 
Vowel-consonant in anagramming-....-.--------------------------------- Popa See nel he tae 4—4¢ 4-2 
Reciprocal: : 
Alpnabet iow uaa site cncey oe pacGeeeteewas Soe caee ee eece 4 Oe Sele Soe a doe oe sae 
Cipher alphabets, keyword mixed tates 
Hncipberment-in Plaviair cioherse: Ju. Lasote oe eck ee eee th eres eee ieee ea cee ege ees 
Polvgraphic substitution: tables... occ ewe eee tie eee ee ee hel etl eee ele 
Reconstruction of matrix..codes: 205.2225 2226. hee costae ose de soe tedee sewed eet ainadiode Joe cele 
Recovery: 
Deécimated: sequences i240 y4 how Asa becepate ca ee halk cbcee pene eeese VE sews ces Seve c 5-92 s-6 
Incompletely-fAlleasmatrix:... 2.03 wo Ss ch aoe week Bese pew tle eh Re ee eee 4-105 4-5 
Matrices: 
Biliteral SVStems: cn4 2/20 2i02 32 fhe Meee ess ots doa Se oe ae twee oleae eel ee Se Sa a8 
POurssquare SVStemsn >. js cle ese eee esa bebe neat eee deed mes erte eee dees 8 LisSe 11-7 
Playfair ciphers. _ eitatn Get ee Sees er ii-24 
EW OssQuaresystémse. ei lyse ote et ee a ee lee eee ee ee ee i Ly-7 
PIGWteR tet Sete ote he ate es oo Pee etn Bet ee ee bee eo hat Pies i-4 
Plaintext Values; Plaviaif-ciphet. . sca. cote. Geslecen ede coe lees oan peek ic atin ieee octet bi-Se train 
Playfair cipher-plaintext: Values 2... 2 eee eve we ce deceeknlne oe oeees Clot wee ed eee ed sand Linke bisis 
Specific Key wc ey tae ee ee ow et ee ae eds winig's eee nee eee ed 2-7 vet 
-Lyansposition matrix dimension’. .222 052 00 oss ced eu ee hee ee oot nee See ese 4-5 
Transposition: mixed sequence. 2. uc. 2o vases ese laace eee ese tbamtct secheves Pea sse ted s-Ta =5 
Reducing digraphs to uniliteral terms_._...._.._.------ ae ne ene eee ee eee ee eee eee tae aa7 
Relationship > 
Cipher to plain: 


Sequences'in progressive key 
Vowel-consonants: 

ANalVsiSs 112 aes Aol e cota. oe ec Oita Shes the ata Se. ste ne Sew eG ee ice es ellen Bete ot teens 

Use 

Relability 


Repeating key periodic polyalphapetic 
Repetitions: 
Condensed table 


Expected polvalphabetic i 
Partial periodic, aperiodic cipher......- 222 22 e sei Sys ect RS ne Bit ne Sor Aars me ante ota eS Norn tet b4-5 
True periodic, aperiodic ciphers...._.___..._-..-------- eee eee ee ee eee eee > 14-3 
Requirements of eryptographic systems............-...--------------- eee eeeeeee e eeeeeee ee! 
Reversed transparencies in two-square svstems____.__-_..--.---.2------------------e eee iss 
Reversed standard etpher alphabet identification. 2-9 
Reversed writing.._.- Be AB Ge ee cat A ME pan teh nth ane ae A Late, Sead 2 AL Mee Ee cote jot 
Reversible encipherment, Playfair cipher.....-._........ 2.2 2-2-2 eee eee eee eee: tl-14 
bane nn een ~ 


Routes of inscription: 
Four-square systems_.-....._.- fh who) dst ee Boe ote Bad ole Me Che te aes en es oe econ ees 11-3a(2) Lil-+ 
‘Transposition Svst€mswiota du ck bo eae a eee en ele ee eee Cae Rene ee gS ion tn a) 3-55 3-1 
betas : 


Index 12 SONFIDENTFAL- 


-GONFIDENTIAL- 


Same: Paragraph Page 
Beginnings, special solutions of transposition systems_._..___.-.------------------------------ t-13a 4-13 
Endings, special solutions of transposition systems_.._--...----.---------------------------- 4-13d 4-15 
Length message, special solutions of transposition systems_._.....---------------------------- 4-l4a 4-15 

Sovtaleckmiet ob et ae ee oes se ee Ue ete a ee ee ale ae a Sand cate disuse 1-60 1-2 

Secret communications origins_____--...-._----..--- 2 eee ee ee ee ee eee 1-66 1-2 

Security : 

Long term...---- be eetegeg-eacegt-besse cess se lesses teeecetede sete eects eee ee esse es 2-26 2-1 
Short term. 2224s 5. Jee kescse eas Silat ges ace ow Sooke ee Seema taaed Deiat = 2-26 2-1 
Cryptographic. systets/.2. 00. os scoes toh encseekecaschJeveleo se one ietSeeu teary a ece 2-1. 2-1 
" y 2a eect ant Oe bbe ee S AAS ND gl Roy Sone acta h bgt! Ae altos cepts = F 

Keyed columnartransposition...._.---.-..---------------------------+------------------- 3-12¢ 3-6 
Multiliteralisubstitution<.22~c2<52c2-cauc5 lcc20252 200 pes epe eee mets sie dodaci te seekks 9-le 9-1 
Polygraphie substitution.......-..2--.-2-2--e2-ss-5-s+ seen ee eee cee nee Foci eum ewe basen 10-2b 10-2 
Selection of generatrix, periodic ciphers.._-......---------------------------------- Ste eee 13-5a 13-5 

Sa Poe oe obe cite a pees " e : ss 
iz Stermination: . scccec coc Poa cen ede Boe okey a deca luetet cheese Sek “8 =Gb (4) - 5-8 


Short. term: security o.coce Goud see law. cece oe lacum es eget e ath hacenweu ud deeete estes a Sete oe 
Signal communications, see definitions. 
Simple grilles: 
Constructions vi2t oo Sse sotececsesce eee se eee te See cal octane eee sees 
Oberatlones oc scot see osteo seam eee eeedodhs eee See thos ced cage lees Sees toe tet 


Solutions 


‘sf 
onoalphabetic.clphers.: 3.020. eevee seen bee eee gecte eee bbls at sees eeeecee seen 
Poly graphiccsubstitution= 66-2 boe oot ecw cage dc de bestest aso t teem scedeeteescobotes 
~ S voit EE 
Special: 
Periodic ciphers. 22 ce eee ots eke Cod estes ce eee ene ee Se oes 13-17a, is-Lse 13-19, 
< iS-2+ 
Transposition: 
Same beginnings. <0 Vast eee lo sete ead es Sosa cee ee See ees 4-13a 4-123 
DAMEVENGIN B52. W 5 Le Se a eee nc ee cyanea Sw redo tn ce bee ets SR ya et 4-13d * s-15 
Same length:messages 3. ssn te cea nsec ecee bode eed aad aceeet eed cad ecereane +-—l4a 4-15 
Specific kev; recovery s2.c22s 2 cso<5 oe eee ee ee su Ue 2-7 2-+ 
Stacked cycles, analysis of, in aperiodic ciphers..._...-..---.-.-.------------- Bin, Daa ob ets 14-6a 14-9 
Standard-cipher alphanéet 22% 22sec ko a tee eS ee oe Ee ee ce el pe ee coke 7-46 7-2 
Steps ofseryptandlysiss 1.200. besa oe ut Sow enttaaione adie messed owed ede eee ekat eee 2-95 2-4 
Stereotypes common to military operations.............-.----.----------------- eee eee eee: 4-1l2a 4-15 
‘ kee FP eS Bai * EARNa RE Ce eR re Cae, OV ey MERE AA ROI E PPR OM StS ROR Ee SE REET > ye] 
Substituting deduced values_....---....-222 20 ee eee eee eee eee 8-164 S-i7 
Successive words produced by aperiodic ciphers._._._........-.-.--------- 22 eee eee eee 14-2c l+- 
Superimposed message, use of, in solution of progressive key...-...-.------------------ ot et oes 4-l4te £16 
Superimposed text, analysis of, in aperiodic cipher......-_-.-----------2------------- banc hele Sate 
aware es EERE ne, ae sib has inated : el 
Suppression of periodicity in aperiodic eiphers_ Bae Botte Se tee eet Oe elas Di ett tee pM ee ance 
Syllabary codes: See 2 
Classific&tionz eo: s.ce00 wos See ecatie et) ele iow taeews eee ett ets oP NAT : 15-2d 15-4 
Equivalencies of, in cipher to plain....-....--22 ee ee ee ee eee ee eee 15-10¢ 15-10 
Uniliteral terms of, in cipher to plain._._-.___....--_ 1.2.22 eee eee ee Sat ioheeed 15-10e 15-10 
Syllabary spelling, analysis of, in matrix codes_._.._._......----.------------ eee eee ee eee eee 15-116 15-11 
Syllabary squares, analysis of : ‘ates 15-9 
l4—4e 14-4 


CONFIDENTIAL — © Index 13 


Systems cryptographic: Paragraph 
Application__-_-.- = 2-1d 
Exploitation 2-3 
Wléxibility 22sec shee se tet tlk ook eus Seen Senee ase sees cwettwwcsasaecuwcbee ses tseeecsueesias 2-le 
Rapidity coos a Sods ete eke tebe coke Pee eee se ads eee Lege deed eesti 2-16 
Reliability. .- 2222. ose J<S0 el cheeses tec aee bak Sees eee ee see eee ee keke 2-la 
Requirements i322 eee See eee ee ee oe la ee teed tee SS 2-1 
Security.__-.- Ee - feed aee 2-16 

2-324 


Soundnesssic..o2e2 cot oe je oe see wettien cde fou Fol ecw ett Sees oss weet ass eee Bete Bese 


tesa t as 


Text beginnings, analysis of, in aperiodic ciphers..._..._--------------------------------------e- 
Traffic analysis: 
Definitionuccscssoigel betes ee se chee Se Sheet eee eons oe Soe bePue Seales Uo eee 
PUrpOseS wien. to 2/3 so es A Gee eae Aas eee Eos Ree CLUS We SRR Set Oe oka 
Transparencies: 
Direct itwo-sduare. 22s etic leg. os ey alk Lhe eb et te ini ek ei te be ee 
Reversed tw ossquares <ssiw iste chee eted eds ecalchcebeoeate uo sct eee osashegeeen se send 
Test for two-squar 
Transposition: 
Ciphérisvstemse os hes eee eee god eee tee eee coll ch ee cee hse cote ee a 
GolWnneTr 2. ses secre ae el cts bid sts eet tle bee oe eee ee eS See eee eed eo ees 


Trigraphs; lise of, insanugrammings.. i. 2cee cus see Sele Sood eee cee oti Sedetece seme? eee 
Triliteral frequency. distribution.2c. 2202. ec 2eee cece oes oe, Sl et ee eee et Sete eee et 


oo aA hte oe Ad Menasha Sea a eh eed One Sone hea 


S-1 


3 
D-ile 
4 
Fi 


RQ 


Ley 


R 


True periodic repetition in aperiodic ciphers....._...-.----------- eee eee eee eee 14-38 
Two=part codesiwc.2s nese acsecseesied So wba taeda ov bei sus eet cee emoreau oben 15-1612) 
Two-square cipher systems: 

Digraphic text ll-5a 

Direct transparencies ll-5a 

Horizontal analysis ll-6a 

Pdentificationuc .-accc scot ave ol eee cose ae eee Bek eee he eos be eee ee toe ea l1-ta 
Matrix: ; 

Columnar order 11-6a:33 

Horizontal so soe oo ee ee ea ee tibet cea cab Saichce foe Ba oe See tel 10-30 

Retovery.« co2oseteike ese enc deeee sles Petteece medal eeteee bet ee eee Sete ot ee es 11-6a(2) 

Verti¢al.o22 2024 2th s2 ace lecee shes ecclc task cere eee tan cheb tise iow eee cee eee eeees 10-3¢ 

Polygraphic.. - Ll-ta 

Reversed transparencies Ll-5a 

1l~6c, Li-6d 

ll-5a 

T-1Ua 

79a 

7-9e 

1-125(1)(6) 


Index 14 


toi 
a ie) E 
mr re to oe 


tO to to "9 Wo to 


! 
Wo pre 


! 
ao 


He bo bore 
Hm ta ta 


| 


wo ty 


>) 
2 


CONFIDENTIAL 


Uniliteral frequency distribution: Paragraph Page 
As solution aid 7-lla 7-7 
Characteristics 2~1lc 2-6 
Comparisons: +c se. et echoes ate eee ee ee Eel eee eS SS ies abet 7-110 7-8 
Pnglishes bocce le seas ee 2c Ps se ee De ns tee et ea 2-11b 9-6 
Us@ec wee Sesel eee cee ese Soho se oct eee tei eee ete ee tees cowie Ss wemce me 2-12 2-7 

Uniliteral terms: 

Reducing digraphs: 262-25 uo. eee ose eS ec athe ete te ote te ees de Slee PON tate 9—Se 9-7 
Special solutions in periodic ciphers...52.2 suse ee boos ens c eh cece eel ieee e tee eed 13-18e 13-24 

Unrelated polyalphabetic cipher alphabets___..__.._--_--.-.-~---------~---~---------------- +e 12-4a(1) 40-3 

Upper and: lower case code systemiscs ssnccocS esse mee ease stei sees seege. chen ser le beet deus 15~2c 15-3 

Use: 

Blanks in monome-dinome systems. 

Condensed table of repetitions. ---------------------~+----------~----------+-+-----+--------- 

fidex of coincidence, polyalphabetic +] 

Phi test 2-15c 2-12 

Phi tests polyalpnabetie: systemse sos. cece csl ede bl sees ee ed ee ete eeese te edees Fee 12-8 
st variant form in polyaiphabetic SYSIGMSS 62 de oe ee eee ok Sot ee cee eS 0 


hy ae 


c iN 
Pal coral eectener GIStPIDUTIONS = on non a ce oe eee metesaua end eeroosGes vlad ace 
Uniliteral frequency distribtitions: no. cise. cee eee tle eee eee ee ets eet beens ee eee ete 
Vowelseonsonant relationships. ics ctcce cee oleae este ee ee Joes ee ek bk owe oe 
Variable grouping, encipherment of avériodi¢. ciphers....2:-.cccscscesossteseue sled eters tte se it-3a i4-2 
Variant forms: 
WReved eGlumnar transposition. ost. et. ee bese ete ee Ge soa oo ede se Eee eee Ss-15 3-7 
Alultiliteralststeiss awit ee see ot eee tee eth sae el ls oe Be Meee oo eRe G-—95 g-8 
Poliygraphic encip! 10—4¢ 10-4 
Vertical: 
Two-square mat 1O- 
Two-squure 2mgivs li-il 
Vowel-consonant: 
Deter mination S-l7a@ S+158 
Relationships, u Sled S-14 
Relatioushine: wnNalvsiss...veswsessce oe skeet ecdes oe shee ateee eset ee cence ieee $-lia 8-13 
payed sto Si Rane ete tare dS ait A tes Meee att aM tan eA ah ae ot SA fe S-l5e 8-16 
bo haat ply at ln Mee eee Ht eine epee re ari Spee ea a BY Ras ees 1-8d i-5 
= WwW. C. WEST) ae ere ia 
General, United States Army, 


rad 


Chie? of Staff. 


pasties 
KENNETH G. WICKHAM, 
Major General, United States Army, 
The Adjutant General. 


Distribution: 
To be distributed in accordance with DA Form 12-12, Sec IT requirements for training publications, 


pertinent to TOE 32-52, 32-56, 32-77 and 32-500. 


CONFIDENTIAL Index 15 


U.S. GOVERNMENT PRINTING OFFICE: 1972 O - 468-095 


